Missing content security policy header cvss July 8, 2019 16 32 64 128 Content spoofing poc Microsoft xss