CORS Misconfigurations


Cross-Origin Resource Sharing (CORS) is a technology used by websites to make web browsers relax the Same Origin Policy, enabling cross-domain communication between different websites.

Bussines Impact

An attacker may exploit the misconfigured CORS to potentially get users sensitive data or even their session.


Use the Access-Control-Allow-Origin header to restrict which domains can make cross-origin requests to the web server.


