vendor:
Limo Booking Software
by:
nu11secur1ty
6.1
CVSS
HIGH
Cross-Origin Resource Sharing (CORS)
CWE
Product Name: Limo Booking Software
Affected Version From:
Affected Version To:
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
2023
Limo Booking Software v1.0 – CORS
The application implements an HTML5 cross-origin resource sharing (CORS) policy for this request that allows access from any domain. The application allowed access from the requested origin http://wioydcbiourl.com. Since the Vary: Origin header was not present in the response, reverse proxies and intermediate servers may cache it. This may enable an attacker to carry out cache poisoning attacks. The attacker can get some of the software resources of the victim without the victim knowing this.