CWE-623

Unsafe ActiveX Control Marked Safe For Scripting

High

Description

An ActiveX control is intended for restricted use, but it has been marked as safe-for-scripting.

Potential Impact

How to Fix

Architecture and Design

During development, do not mark it as safe for scripting.

System Configuration

After distribution, you can set the kill bit for the control so that it is not accessible from Internet Explorer.

Related Weaknesses

References

View on MITRE CWE Database →

Need Help Fixing This Vulnerability?

Our security experts can help you identify and remediate CWE-623 vulnerabilities in your codebase.

Get Security Assessment