Writeups
-
Easy
CORS vulnerability with trusted insecure protocols
cors that trusts any subdomain over any protocol, chained with a reflected xss on an insecure http stock subdomain to run the credentialed accountDetails read from a trusted origin and exfiltrate the admin api key
Cross-Origin Resource Sharing (CORS) 3 min -
Easy
CORS vulnerability with trusted null origin
cors that trusts only the null origin
Cross-Origin Resource Sharing (CORS) 4 min -
Easy
CORS vulnerability with basic origin reflection
cors misconfiguration that reflects any origin and allows credentials
Cross-Origin Resource Sharing (CORS) 3 min
Nothing matched that.
No writeups here yet. Try a broader tag, or clear the filter to see everything.
Clear filters