Комментарии:
@Byte Blogger baseHow Many Members Waiting @krishnsec Methodology And Podcast
ОтветитьI want to ask impact of this because it is unauthenticated please reply
ОтветитьOsm
ОтветитьTrust me, there is no impact at all. What is he blindly trying to do is to make it look like CORS vuln without a clear understanding. There is no impact at all, cause by defautl, the URL itself is already public. What is he doing is just capture all the resonse into his browser. That's all =)) If any program rewards him for this, I think that program does not know about security =))
ОтветитьNA
ОтветитьI think that is just a Bad implementation, but i don't see any sensitive info. getting disclosed which I can capture in my log..
ОтветитьI got same cors vulnerability is this any impact and will i get any bounty ?
ОтветитьIt's like an XSS it's similar to xss okay thank you for that sir.
ОтветитьBounty kitni mili or kis level ka bug hai
ОтветитьI found same Vulnerability in /wp-json/wp/v2/users is it a valid bug. Please reply
Ответить