Exploiting XSS via CORS trust relationships
GET /api/requestApiKey HTTP/1.1
Host: vulnerable-website.com
Origin: https://subdomain.vulnerable-website.com
Cookie: sessionid=...HTTP/1.1 200 OK
Access-Control-Allow-Origin: https://subdomain.vulnerable-website.com
Access-Control-Allow-Credentials: truehttps://subdomain.vulnerable-website.com/?xss=<script>cors-stuff-here</script>Last updated