HTML to exploit CORS misconfigurations Download this file and edit it Change the domain which calls the server with ACAO and ACAC header responses Save the html file Call it from within the browser instance to which Burp is proxied You should be able to steal (popup in this case) the ids which are present in the called subdomain