4 ms·
Theory is that an attacker can bypass CSRF protections when CORS is disabled by making an extra GET request to parse the CSRF token which is then provided in th
by cwilby 5y ago
Theory is that an attacker can bypass CSRF protections when CORS is disabled by making an extra GET request to parse the CSRF token which is then provided in the next request.
- cwilby 5y agoThen again, I suppose a dedicated attacker can just bypass CORS.