ah8r / csrf

CSRF Scanner Extension for Burp Suite Pro
GNU General Public License v3.0
19 stars 17 forks source link

Detection Update #11

Closed prodigysml closed 6 years ago

prodigysml commented 6 years ago

Remove all false positive in relation to Content-Type being application/json and Access-Control-Allow-Origin: not being set in the response.

A fair few false positives come up from this

prodigysml commented 6 years ago

Don't worry about it actually. Found a way to exploit it in older browsers :)