Files
nuclei-templates/security-misconfiguration/basic-cors.yaml
2020-05-09 10:59:35 +02:00

19 lines
356 B
YAML

id: basic-cors-misconfig
info:
name: Basic CORS misconfiguration
author: nadino
severity: medium
requests:
- method: GET
path:
- "{{BaseURL}}"
headers:
Origin: https://evil.com
matchers:
- type: word
words:
- 'Access-Control-Allow-Origin: https://evil.com'
part: header