| |
Vulnerability CVE-2024-0310
Published: 2024-01-10
| Description: |
A content-security-policy vulnerability in ENS Control browser extension prior to 10.7.0 Update 15 allows a remote attacker to alter the response header parameter setting to switch the content security policy into report-only mode, allowing an attacker to bypass the content-security-policy configuration.
|
Type:
CWE-79 (Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'))
References: |
https://kcm.trellix.com/corporate/index?page=content&id=SB10417
|
|
|
closedb();
?>
Copyright 2026, cxsecurity.com
|
|
|