PT-2026-34541 · Beghelli · Sicuroweb
Jean-Marie Bourbon
+1
·
Published
2026-04-22
·
Updated
2026-04-23
·
CVE-2026-41469
CVSS v3.1
5.2
Medium
| Vector | AV:A/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Beghelli Sicuro24 SicuroWeb (affected versions not specified)
Description
Beghelli Sicuro24 SicuroWeb does not enforce a Content Security Policy (CSP), which is a security layer that helps detect and mitigate certain types of attacks, including Cross-Site Scripting (XSS) and data injection attacks. This absence allows the unrestricted loading of external JavaScript resources from attacker-controlled origins. When combined with template injection and sandbox escape issues within the application, this lack of CSP removes browser-enforced restrictions, enabling the loading of arbitrary remote payloads into operator browser sessions.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Protection Mechanism Failure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sicuroweb