Home Cross-Origin Resource Sharing
Post
Cancel

Cross-Origin Resource Sharing

Cross-Origin Resource Sharing

Cross-origin resource sharing (CORS) is a browser mechanism which enables controlled access to resources located outside of a given domain. It extends and adds flexibility to the same-origin policy (SOP). However, it also provides potential for cross-domain attacks, if a website’s CORS policy is poorly configured and implemented. CORS is not a protection against cross-origin attacks such as cross-site request forgery (CSRF).

Exploitation

References

This post is licensed under CC BY 4.0 by the author.