View Categories

The Browser Is Not Prevented From Inferring The MIME Type From The Document Content And From Executing Malicious Files

Impact Area

Security

Severity

Medium

Affected Element

Org Config

Rule ID #

SF-0163

Impact #

Increased vulnerability to code injection attacks by Javascript or StyleSheet code.

Remediation #

Enable this setting. From Setup, enter “Session Settings” in the Quick Find box, then select Session Settings. Then enable “Content Sniffing protection”.

Time to fix

30 min

References #

This rule is linked to Common Weakness Enumeration CWE-79 Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’).

Powered by BetterDocs