π
Notes
β
Ctrl
k
For the complete documentation index, see
llms.txt
. This page is also available as
Markdown
.
Copy
On this page
CyberSecurity
Penetration Testing
PortSwigger
Cross-origin resource sharing (CORS)
Vulnerabilities arising from Misconfigurations
Server-generated ACAO header from client-specified Origin header
Errors parsing Origin headers
Whitelisted null origin value
Exploiting XSS via CORS trust relationships
Breaking TLS with poorly configured CORS
Intranets and CORS without credentials
Mitigations
Previous
Access-Control-Allow-Origin response header
Next
Server-generated ACAO header from client-specified Origin header
Last updated
3 years ago