The Burp Suite User Forum was discontinued on the 1st November 2024.

Burp Suite User Forum

For support requests, go to the Support Center. To discuss with other Burp users, head to our Discord page.

SUPPORT CENTER DISCORD

Exploiting CORS with JWT token

Loan | Last updated: Aug 23, 2022 08:57AM UTC

Hi, I was wondering if CORS misconfigurations are exploitable if the vulnerable application uses an Authorization header with a JWT token to manage authorizations, instead of cookies. As of my tests, the JWT token is not automatically included in the request made by the victim, is there a way to have it included ? Many thanks!

Hannah, PortSwigger Agent | Last updated: Aug 23, 2022 09:07AM UTC