The Burp Suite User Forum was discontinued on the 1st November 2024.

Burp Suite User Forum

For support requests, go to the Support Center. To discuss with other Burp users, head to our Discord page.

SUPPORT CENTER DISCORD

Lab: CORS vulnerability with internal network pivot attack

Elliott | Last updated: Dec 24, 2022 04:23AM UTC

I'm having a hard time connecting the CORS vulnerability for this lab. Initially I was thinking that after finding the intranet, the goal would've been to implement some kind of xss back on the shop site, e.g. `https://YOUR_LAB_ID.web-security-academy.net/admin` to access the admin panel and delete a user, how is it different than any other xss exploit where we're relying on the user to be logged in after delivering the exploit? Really enjoying the content and labs, Thanks!

Liam, PortSwigger Agent | Last updated: Dec 28, 2022 12:36PM UTC

Thanks for your message, Elliot. Have you checked out this video solution? - https://www.youtube.com/watch?v=8v9StgfIv5A

Elliott | Last updated: Dec 29, 2022 02:15PM UTC