CVE-2024-0310: XSS
A content-security-policy vulnerability in ENS Control browser extension prior to 10.7.0 Update 15 allows a remote attacker to alter the response header parameter setting to switch the content security policy into report-only mode, allowing an attacker to bypass the content-security-policy configuration.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-0310?
CVE-2024-0310 has a moderate severity level due to its potential to allow attackers to bypass security configurations.
How do I fix CVE-2024-0310?
To fix CVE-2024-0310, update the ENS Control browser extension to version 10.7.0 or later.
What systems are affected by CVE-2024-0310?
CVE-2024-0310 affects versions of the ENS Control browser extension prior to 10.7.0 Update 15.
Can CVE-2024-0310 be exploited locally?
CVE-2024-0310 is primarily a remote attack vector and does not require local access to exploit.
Is Microsoft Windows vulnerable to CVE-2024-0310?
Microsoft Windows itself is not vulnerable to CVE-2024-0310, but the Ens Control browser extension within it is.