Burp Suite User Forum

Create new post

CORS issue not highlighted by Burp

Luca | Last updated: Oct 29, 2020 10:11AM UTC

Hello, I have an application which for some requests returns Access-Control-Allow-Origin: * Access-Control-Expose-Headers: x-filename I have active scanned the request with Burp but it doesn't report the CORS issue at all. What could be the reason? Is it possible that Burp only reports that if there is also Access-Control-Allow-Credentials: true ? Thank you in advance.

Michelle, PortSwigger Agent | Last updated: Oct 30, 2020 11:56AM UTC

Hi Would you be happy to share a bit more detail with us directly so we can take a closer look? If so can you send an email to support@portswigger.net, please? What scan configuration settings were assigned to the active scan? Would you be happy to share a sample request and response?

You must be an existing, logged-in customer to reply to a thread. Please email us for additional support.