As detailed in this blog post, failing to set the form-action CSP directive can lead to data being sent to unauthorizeddomains.

If some rogue JS executes on a page with a form, that JS could be used to change the form's action attribute to evil.com, for example.
Adding the ability to set the form-action CSP directive would prevent form submission in this scenario.

Comments

milodesc created an issue. See original summary.

melonangie’s picture

StatusFileSize
new1.12 KB
the_g_bomb’s picture

Updated URL for the relevant blog post:
https://david-gilbertson.medium.com/im-harvesting-credit-card-numbers-an...
I think it may no longer be available on hackernoon even though it still shows up in the search results

the_g_bomb’s picture

Status: Active » Closed (duplicate)

Closing as a duplicate of #3219294: Add form-action directive

Now that this issue is closed, review the contribution record.

As a contributor, attribute any organization that helped you, or if you volunteered your own time.

Maintainers, credit people who helped resolve this issue.