A Flask application (login admin/admin) whose /confidential page holds private data and answers cross-origin requests with credentials allowed.
Pas commencéDockercommit 596f3f4x86_64 · aarch64Secret
Read the logged-in victim's confidential data from a page on another origin by abusing the CORS policy.
Le brief de ce lab se trouve dans son dépôt.