CORS Misconfiguration
Summary
Tools
Prerequisites
Exploitation
Vulnerable Example: Origin Reflection
Vulnerable Implementation
Proof of concept
Vulnerable Example: Null Origin
Vulnerable Implementation
Proof of concept
Vulnerable Example: XSS on Trusted Origin
Vulnerable Example: Wildcard Origin * without Credentials
* without CredentialsVulnerable Implementation
Proof of concept
Vulnerable Example: Expanding the Origin / Regex Issues
Vulnerable Implementation (Example 1)
Proof of concept (Example 1)
Vulnerable Implementation (Example 2)
Proof of concept (Example 2)
Bug Bounty reports
References
Last updated