The Browser Is Not Prevented From Inferring The MIME Type From The Document Content And From Executing Malicious Files

< 1 min read

Impact Area

Security

Severity

Medium

Affected Element

Org Config

Rule ID #

SF-0163

Impact #

Increased vulnerability to code injection attacks by Javascript or StyleSheet code.

Remediation #

Enable this setting. From Setup, enter “Session Settings” in the Quick Find box, then select Session Settings. Then enable “Content Sniffing protection”.

Time to fix #

30 min

References #

This rule is linked to Common Weakness Enumeration CWE-79 Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’).

Updated on March 21, 2025
Was it helpful ?