Collected research
CORS vulnerabilities: Weaponizing permissive CORS configurations
Exploiting trust: Weaponizing permissive CORS configurations
A scan of every domain in a managed pentest estate for permissive Cross-Origin Resource Sharing, followed by exploitation, argues such findings are routinely under-rated. The article classifies the origin-validation errors seen: unconditional reflection of Origin, trusting the null origin a sandboxed iframe can send, prefix matching on the trusted domain or localhost, and blanket subdomain trust. Case studies reach session theft and account takeover.
Record
- Document
- Exploiting trust: Weaponizing permissive CORS configurations
- Researcher
- Thomas Stacey
- Published by
- Outpost24
- Date
- Topic
- Other
In the archive
Related sources
Tags
This page is the archive's own catalogue record. The research is the work of Thomas Stacey, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .