vendor:
craftercms
by:
nu11secur1ty
7.5
CVSS
HIGH
Cross-Origin Resource Sharing (CORS)
352
CWE
Product Name: craftercms
Affected Version From: 4.x.x
Affected Version To: 4.x.x
Patch Exists: NO
Related CWE:
CPE: a:craftercms:craftercms:4.x.x
Platforms Tested:
2023
craftercms 4.x.x – CORS
The application implements an HTML5 cross-origin resource sharing (CORS) policy for this request that allows access from any domain. The application allowed access from the requested origin pwnedhost1.com which domain is on the attacker. The application allows two-way interaction from the pwnedhost1.com origin. This effectively means that any domain can perform two-way interaction by causing the browser to submit the null origin, for example by issuing the request from a sandboxed iframe. The attacker can use some library of the victim and this can be very dangerous!
Mitigation:
Implement a strong CORS policy that only allows access from trusted domains.