origin-header-manipulation

1 article
sort: new top best
clear filter
0 5/10
vulnerability

A CORS bypass technique exploiting improper Origin header validation by injecting the target domain as a subdomain of the attacker's domain (e.g., redact.com.attacker.com), allowing credential-enabled requests to leak sensitive account information from the victim site.

Saad Ahmed
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 17 hours ago · details