Description
Incorrectly configured Content Security Policy could expose an application against client-side threats including Cross-Site Scripting, Cross Frame Scripting, and Cross-Site Request Forgery, etc.
Bussines Impact
Configuring Content Security Policy (CSP) involves the Content-Security-Policy (CSP) HTTP header to a Web page and giving values to control what resources the user agent is allowed to load for that page.
Recommendation
Make sure all headers are set up correctly.