vulns.co
/
GKData.io MCP

Back to Playbooks

CORS Misconfiguration

Abuse permissive cross-origin policies to read authenticated responses from a victim's browser.

Tags: cors, authz, data-theft

Level: intermediate

Method

  1. Probe ACAO reflection

    Send an Origin header and see if it's reflected in Access-Control-Allow-Origin, especially with Access-Control-Allow-Credentials: true.

    curl -s -H 'Origin: https://evil.com' https://target.com/api/me -I

    Tools: httpx

  2. Test weak validation

    Try null origin, suffix/prefix matches (target.com.evil.com), and unescaped-dot regex bypasses.

    curl -s -H 'Origin: null' https://target.com/api/me -I
  3. Exploit

    Host a page that fetches the victim's authenticated endpoint with credentials and exfiltrates the response. Impact = account data theft.

Field notes

  • Reflected Origin + Allow-Credentials:true is almost always a finding.
  • null origin is reachable via a sandboxed iframe or data: URL.

References