0
Closed

cors 403 error page vulnerability scan

Eric Frace 7 years ago updated by swhite (Product Manager) 12 months ago 1

Tests ran through Acunetix come up with a result of 'Insecure CORS configuration' due to the issue mentioned in this post:

https://github.com/balderdashy/sails/issues/3862

I have worked with Control support, and they have confirmed that the POST is getting a 403/ forbidden error that is causing this issue. Contained in that link is an example of how the 403 error can be resolved to no longer show this vulnerability in Acunetix. Our auditors are unsatisfied with the results, so it would be great if we could get this resolved.