The Burp Suite User Forum was discontinued on the 1st November 2024.

Burp Suite User Forum

For support requests, go to the Support Center. To discuss with other Burp users, head to our Discord page.

SUPPORT CENTER DISCORD

CORS vulnerability with trusted null origin: Origin header null for XHR request made from <iframe> with sandbox attribute

Chuong | Last updated: Oct 15, 2023 01:30PM UTC

Hello everyone, I am doing Lab CORS vulnerability with trusted null origin and bypassing this using iframe along with sandbox attribute. I read this article but still find it confusing: https://stackoverflow.com/questions/44764338/origin-header-null-for-xhr-request-made-from-iframe-with-sandbox-attribute Can someone explain it to me? One more problem why can't I solve cors lab with fetch() instead of XMLHttpRequest. Thank you!

Michelle, PortSwigger Agent | Last updated: Oct 16, 2023 08:56AM UTC