Cors Misconfig

CORS misconfiguration allows attacker-controlled origins to read sensitive cross-origin responses when servers echo the `Origin` header in `Access-Control-Allow-Origin` or set it to `*` with `Access-Control-Allow-Credentials: true`. Detect via `Origin: https://attacker.com` reflection in `Access-Control-Allow-Origin` response header, wildcard `*` on credentialed endpoints, and null origin acceptance. Tools: OWASP ZAP, Burp Suite, manual `fetch()` with `credentials: include`.

ShulkwiSEC Updated 21 repo stars

File contents

ShulkwiSEC/bb-huge/tree/main/skills/curated/cors-misconfig commit 13ff0ee6fe

Frequently asked questions

npx skillmds@latest add shulkwisec/cors-misconfig