Incorrect Cross-Origin Resource Sharing (CORS)...
Moderate severity
Unreviewed
Published
Oct 2, 2025
to the GitHub Advisory Database
Description
Published by the National Vulnerability Database
Oct 2, 2025
Published to the GitHub Advisory Database
Oct 2, 2025
Incorrect Cross-Origin Resource Sharing (CORS) configuration in Hiberus Sintra. Cross-Origin Resource Sharing (CORS) allows browsers to make cross-domain requests in a controlled manner. This request has an “Origin” header that identifies the domain making the initial request and defines the protocol between a browser and a server to see if the request is allowed. An attacker can exploit this and potentially perform privileged actions and access confidential information when Access-Control-Allow-Credentials is enabled.
References