Detail
Tests an http server for Cross-Origin Resource Sharing (CORS), a way for domains to explicitly opt in to having certain methods invoked by another domain.
The script works by setting the Access-Control-Request-Method header field for certain enumerated methods in OPTIONS requests, and checking the responses.
Solution Advice
Only use components that do not have known vulnerabilities, only use components that, when combined, do not introduce a security vulnerability, and ensure that a misconfiguration does not cause any vulnerabilities.
Get AI-powered remediation steps tailored to your asset.
Try AI Solutions →