Member-only story

This bug is one of my effortless findings since I only found it on scanner. But still acknowledge by the developer and get a reward.
So what is cors?
Cross-origin resource sharing (CORS) is a browser mechanism which enables controlled access to resources located outside of a given domain. It extends and adds flexibility to the same-origin policy (SOP). However, it also provides potential for cross-domain attacks, if a website’s CORS policy is poorly configured and implemented. CORS is not a protection against cross-origin attacks such as cross-site request forgery (CSRF).

Story of findings,
So there I was, grinding away on my favorite earning site — you know, one of those places where you can make a few cents doing tasks, clicking ads, playing games, and other digital side quests. It’s not exactly a gold mine, but hey, every penny counts, right?
It was just another normal day, me clicking away like a dedicated internet worker. But man, my earnings were horrendous. I spent four hours clicking, watching ads, and completing tasks, only to look at my balance and see… a whopping $2. Yup, TWO DOLLARS. At that…