Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Access-Control-Allow-Origin Header not correctly detected #10

Open
c4ir0 opened this issue Jul 31, 2022 · 0 comments
Open

Access-Control-Allow-Origin Header not correctly detected #10

c4ir0 opened this issue Jul 31, 2022 · 0 comments

Comments

@c4ir0
Copy link

c4ir0 commented Jul 31, 2022

despite the importance of the tool and it's purpose ( I really appreciate it ) but the results was not promising in some situation, for example on trying the tool
1
the result was as above and the cause was presented 0a7600c1033c1375c0b5ac1800ae0002.web-security-academy.net/my-account - Not vulnerable: Access-Control-Allow-Origin header not present
while I (the solution OC) just added the Origin: hello.com header to detect it
2

I suggest with ❤ U may add the header automatically if not presented in the original request that could increase the chance to detect the Vulnerability .

@ic0ns ic0ns changed the title ⚠❤⚠ Access-Control-Allow-Origin Header not correctly detected Aug 1, 2022
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant