Beghelli Sicuro24 SicuroWeb does not enforce a Content Security Policy, allowing unrestricted loading of external JavaScript resources from attacker-controlled origins. When chained with the template injection and sandbox escape vulnerabilities present in the same application, the absence of CSP removes the browser-enforced restriction that would otherwise block external script execution, enabling attackers to load arbitrary remote payloads into operator browser sessions.
References
Configurations
No configuration.
History
22 Apr 2026, 19:17
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-04-22 19:17
Updated : 2026-04-22 21:18
NVD link : CVE-2026-41469
Mitre link : CVE-2026-41469
CVE.ORG link : CVE-2026-41469
JSON object : View
Products Affected
No product.
CWE
CWE-693
Protection Mechanism Failure
