Cookie fixation

CSP flaws: cookie fixation

TL;DR: CSP can’t block <meta http-equiv="Set-Cookie" content="a=b">. XSS vulnerability on a page with CSP can still be source for attacks that are based on writing cookies. Let’s take a look at some examples of cookie fixation issues.