A content-security-policy vulnerability in ENS Control browser extension prior to 10.7.0 Update 15 allows a remote attacker to alter the response header parameter setting to switch the content security policy into report-only mode, allowing an attacker to bypass the content-security-policy configuration.
2024-01-10T11:15:10.580
2024-11-21T08:46:17.807
Modified
CVSSv3.1: 6.1 (MEDIUM)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | trellix | endpoint_security_web_control | < 10.7.0 | Yes |
Application | trellix | endpoint_security_web_control | 10.7.0 | Yes |
Operating System | microsoft | windows | - | No |