Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 27 Apr 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Beghelli
Beghelli sicuroweb (sicuro24) |
|
| Vendors & Products |
Beghelli
Beghelli sicuroweb (sicuro24) |
Wed, 22 Apr 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 22 Apr 2026 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Wed, 22 Apr 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Beghelli Sicuro24 SicuroWeb does not enforce a Content Security Policy, allowing unrestricted loading of external JavaScript resources from attacker-controlled origins. When chained with the template injection and sandbox escape vulnerabilities present in the same application, the absence of CSP removes the browser-enforced restriction that would otherwise block external script execution, enabling attackers to load arbitrary remote payloads into operator browser sessions. | |
| Title | Beghelli Sicuro24 SicuroWeb Missing Content Security Policy | |
| Weaknesses | CWE-693 | |
| References |
|
|
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-04-22T18:56:46.982Z
Reserved: 2026-04-20T16:07:47.311Z
Link: CVE-2026-41469
Updated: 2026-04-22T18:56:29.246Z
Status : Deferred
Published: 2026-04-22T19:17:09.000
Modified: 2026-04-22T21:18:45.917
Link: CVE-2026-41469
No data.
OpenCVE Enrichment
Updated: 2026-04-28T08:00:14Z