The Burp Suite User Forum was discontinued on the 1st November 2024.

Burp Suite User Forum

For support requests, go to the Support Center. To discuss with other Burp users, head to our Discord page.

SUPPORT CENTER DISCORD

CORS issue not highlighted by Burp

Luca | Last updated: Oct 29, 2020 10:11AM UTC

Hello, I have an application which for some requests returns Access-Control-Allow-Origin: * Access-Control-Expose-Headers: x-filename I have active scanned the request with Burp but it doesn't report the CORS issue at all. What could be the reason? Is it possible that Burp only reports that if there is also Access-Control-Allow-Credentials: true ? Thank you in advance.

Michelle, PortSwigger Agent | Last updated: Oct 30, 2020 11:56AM UTC