Wildcard Origin


During the scan, Kayran managed to detect Wildcard Origin.
Cross-Origin Resource Sharing (CORS) is a mechanism that enables web browsers to perform cross-domain requests using the XMLHttpRequest API.
These cross-origin requests have an Origin header, that identifies the domain which sends the request.
It defines the protocol to use between a web browser and a server to determine whether a cross-origin request is allowed or not.

If a website’s CORS policy is misconfigured and implemented, it might lead to raising the potential of cross-domain attacks to occur.


CVSS Version 3.x – 3.1 Low


To prevent this Wildcard Origin, make sure that the server uses “Whitelist”. That will assist in knowing which Origin has sent the request and whether to confirm it or not.





< Return to all Vulnerabilities

Browser Exploitation

We know that it’s possible to exploit weaknesses (or vulnerabilities) that exist in anything, from a certain code to the entire application, let’s talk about

Read More »