Web Hack List

Other nomination

CORS vulnerabilities: Weaponizing permissive CORS configurations

A scan of every domain in a managed pentest estate for permissive Cross-Origin Resource Sharing, followed by exploitation, argues such findings are routinely under-rated. The article classifies the origin-validation errors seen: unconditional reflection of Origin, trusting the null origin a sandboxed iframe can send, prefix matching on the trusted domain or localhost, and blanket subdomain trust. Case studies reach session theft and account takeover.

Record

Researcher
Thomas Stacey
Published by
Outpost24
Date

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of Thomas Stacey, first published at the original source. Preserved copies are kept so the citation survives its host.