cve/2020/CVE-2020-28481.md
2024-05-25 21:48:12 +02:00

820 B

CVE-2020-28481

Description

The package socket.io before 2.4.0 are vulnerable to Insecure Defaults due to CORS Misconfiguration. All domains are whitelisted by default.

POC

Reference

Github