Breaking TLS with poorly configured CORS
GET /api/requestApiKey HTTP/1.1
Host: vulnerable-website.com
Origin: http://trusted-subdomain.vulnerable-website.com
Cookie: sessionid=...HTTP/1.1 200 OK
Access-Control-Allow-Origin: http://trusted-subdomain.vulnerable-website.com
Access-Control-Allow-Credentials: truehttp://trusted-subdomain.vulnerable-website.comhttps://vulnerable-website.comhttp://trusted-subdomain.vulnerable-website.com
Proof of Concept via XSS
Last updated