@0xTib3rius CVSS spec is also sometimes inconsistent, so it's understandable that people get lost. Some concepts are a total mess. When I pointed one of those to the CVSS author on a webinar the answer was "that's the beauty of CVSS" ๐
@0xTib3rius To explain Scope metric you should introduce vulnerable and impacted components, which BTW might be both impacted actually. That's an interesting corner case, which is also improved in the 4.0 version where you set both impacts separetely.
@0xTib3rius Thanks, but the tutorial is a little bit inconsistent and not aligned with the CVSS 3.1 spec. E.g. AV:Network is not just internet, it's clarified in the scoring guidance in spec. Scope change for XSS is because vuln lies in the webapp but you run the js code on the browser.
@0xTib3rius 1) authentication based on http headers, not cookies
2) content- type, that cannot be forged from <form> HTML tag - when server validates it and there is no CORS in use or CORS is properly configured
3) http request type (e.g. PUT) with server side validation of it. CORS as above
@PortSwigger Can't reproduce it now. Tried those two labs and both worked correctly this time. Next time I will collect some evidence and get back to you on email :)