QID 153009
Date Published: 2023-07-26
QID 153009: JavaScript Identified on Payment Page
The scan discovered JavaScript loading on a Payment Page.
Attackers, commonly look for payment pages and load vulnerable scripts. Functionality with those scripts can be altered without user's knowledge and such vulnerability could allow attacker to steal customer's sensitive information.
Solution
Scripts must be authorized either by manual automated process.
Restrict scripts to be loaded from trusted source.
Implement Content Security Policy to prevent unauthorized content being loaded on payment pages.
It is recommended to use Sub-resource integrity SRI when loading scripts from third party sites or CDN.
Restrict scripts to be loaded from trusted source.
Implement Content Security Policy to prevent unauthorized content being loaded on payment pages.
It is recommended to use Sub-resource integrity SRI when loading scripts from third party sites or CDN.
Vendor References
CVEs related to QID 153009
Software Advisories
| Advisory ID | Software | Component | Link |
|---|