The Burp Suite User Forum was discontinued on the 1st November 2024.

Burp Suite User Forum

For support requests, go to the Support Center. To discuss with other Burp users, head to our Discord page.

SUPPORT CENTER DISCORD

CORS lab not functioning properly.

Malinga | Last updated: Dec 19, 2022 11:36AM UTC

CORS labs do not giving intended HTTP results. POC: I tried "CORS vulnerability with trusted null origin" lab with below request GET /accountDetails HTTP/1.1 Host: 0ae900aa03ce9968c2c8b1d200aa00a4.web-security-academy.net Cookie: session=XXXXX Origin: null Below are the result HTTP headers: HTTP/1.1 200 OK Access-Control-Allow-Credentials: true Content-Type: application/json; charset=utf-8 Connection: close Content-Length: 149 I'm not getting access-control-allow-origin header. The same happens with other CORS labs also. Can you please help on this

Michelle, PortSwigger Agent | Last updated: Dec 19, 2022 04:25PM UTC