S4E just found a high top 10 tcp port service scan
medium·Misconfiguration·Updated Jan 3, 2024

HTTP Server Cross-Origin Resource Sharing (CORS) Scanner

HTTP Server Cross-Origin Resource Sharing (CORS) Scanner

Est. Time~15 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
1.1k
Times Used
by S4E users
303
Assets Scanned
domains & IPs
424
Vulnerabilities Found
confirmed findings
Detail

Tests an http server for Cross-Origin Resource Sharing (CORS), a way for domains to explicitly opt in to having certain methods invoked by another domain.

The script works by setting the Access-Control-Request-Method header field for certain enumerated methods in OPTIONS requests, and checking the responses.

Solution Advice

Only use components that do not have known vulnerabilities, only use components that, when combined, do not introduce a security vulnerability, and ensure that a misconfiguration does not cause any vulnerabilities.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.