Is this worth reporting?
I am doing a bug bounty. I found a CORS policy that allows access from any domain. Burp Suite marks this vulnerability as high. Should I report it or just ignore it since technically it requires social engineering, which is out of scope? submitt…