Using Google Analytics for data extraction
Bypassing CSP with Google Analytics

Bypassing CSP with Google Analytics

TL;DR: CSP can’t block <meta http-equiv="Set-Cookie" content="a=b">. XSS vulnerability on a page with CSP can still be source for attacks that are based on writing cookies. Let’s take a look at some examples of cookie fixation issues.

CSP (Content-Security-Policy) is an HTTP response header containing directives that instruct browsers how to restrict contents on a page. For instance, the “form-action” directive restricts what origins forms may be submitted to. The CSP form-action directive can limit which URLs the page may submit forms to. This protection can be bypassed in the case of an XSS/HTML injection bug.