A content-security-policy vulnerability in ENS Control browser extension prior to 10.7.0 Update 15 allows a remote attacker to alter the response header parameter setting to switch the content security policy into report-only mode, allowing an attacker to bypass the content-security-policy configuration.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-16106 | A content-security-policy vulnerability in ENS Control browser extension prior to 10.7.0 Update 15 allows a remote attacker to alter the response header parameter setting to switch the content security policy into report-only mode, allowing an attacker to bypass the content-security-policy configuration. |
No history.
Status: PUBLISHED
Assigner: trellix
Published:
Updated: 2024-09-03T18:29:33.745Z
Reserved: 2024-01-08T06:20:53.953Z
Link: CVE-2024-0310
Updated: 2024-08-01T18:04:49.037Z
Status : Modified
Published: 2024-01-10T11:15:10.580
Modified: 2026-06-17T06:53:14.963
Link: CVE-2024-0310
No data.
OpenCVE Enrichment
No data.
-
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
EUVD