HACKR.GG
LabsCORS Misconfiguration
CORSMedium

CORS Misconfiguration

Critbook reflects any Origin header in its CORS response. Exploit the misconfiguration to make cross-origin requests that leak authenticated data.

↗ View walkthrough
// Machine control
Checking session...
// Submit flag