Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%
Get alerts for future matching vulnerabilitiesLog in to subscribe
I. Basic Information for CVE-2026-41469
Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Beghelli Sicuro24 SicuroWeb Missing Content Security Policy
Source: NVD (National Vulnerability Database)
Vulnerability Description
Beghelli Sicuro24 SicuroWeb does not enforce a Content Security Policy, allowing unrestricted loading of external JavaScript resources from attacker-controlled origins. When chained with the template injection and sandbox escape vulnerabilities present in the same application, the absence of CSP removes the browser-enforced restriction that would otherwise block external script execution, enabling attackers to load arbitrary remote payloads into operator browser sessions.
Source: NVD (National Vulnerability Database)
CVSS Information
CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Source: NVD (National Vulnerability Database)
Vulnerability Type
保护机制失效
Source: NVD (National Vulnerability Database)
Vulnerability Title
Beghelli Sicuro24 SicuroWeb 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Beghelli Sicuro24 SicuroWeb是意大利Beghelli公司的一个远程安防监控与报警管理平台。 Beghelli Sicuro24 SicuroWeb存在安全漏洞,该漏洞源于未强制执行内容安全策略,允许无限制加载来自攻击者控制源的外部JavaScript资源,可能导致加载任意远程有效载荷。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)
Affected Products
VendorProductAffected VersionsCPESubscribe
BeghelliSicuroWeb (Sicuro24) 0 -
II. Public POCs for CVE-2026-41469
#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC
III. Intelligence Information for CVE-2026-41469
Please Login to view more intelligence information
IV. Related Vulnerabilities
V. Comments for CVE-2026-41469

No comments yet


Leave a comment