The application does not control browser functions in a document or within any iframe.
Enable functions that allow an attacker to compromise the confidentiality of application users.
- Enable the header permission policy and disable all functions that your application does not need.
Anonymous attacker from the Internet.
⌚ 30 minutes.
Default score using CVSS 3.1. It may change depending on the context of the src.
Default score using CVSS 4.0. It may change depending on the context of the src.
The The Permissions-Policy header in response
HTTP/1.1 200 OK
Content-Security-Policy: default-src 'self' frame_ancestors
Content-Type: userID/html; charset=utf-8
Permissions-Policy: geolocation=(), camera=(), microphone=()
The Permissions-Policy header dont exist.
HTTP/1.1 200 OK
Content-Security-Policy: default-src 'self' frame_ancestors
Content-Type: userID/html; charset=utf-8