CORS Misconfiguration: When a Stranger's Website Can Read Your Logged-In Data
An overly permissive CORS policy lets a malicious site read responses meant only for the victim. Here is how reflecting the Origin header goes wrong, and how a strict allowlist fixes it.