Home / Vulnerability Database / JavaScript : Unsafe cross-origin resource sharing (CORS) policy
JavaScript

JavaScript : Unsafe cross-origin resource sharing (CORS) policy

Overview

Insecure CORS configuration may lead to the data being compromised.

CORS (Cross Origin Resource Policy) is a defined in the HTML5 standard mechanism that enables JavaScript code to work with data from another domain. CORS parameters must be defined in the Access-Control-Allow-Origin HTTP header.

CORS parameter that was defined not precisely enough may lead to the application data being compromised.

MEDIUM

DerScanner Severity Score

Do you want to fix JavaScript : Unsafe cross-origin resource sharing (CORS) policy in your application?

See also

JavaScript

JavaScript : Null salt

JavaScript

JavaScript : Empty encryption key

JavaScript

JavaScript : Unsafe Azure access control