A surprising number of web CTF challenges hinge on a single misconfigured header. To understand why, you need the rule it's trying to carefully relax: the Same-Origin Policy, and the exception mechanism built on top of it, CORS.
What "origin" actually means
Two URLs share an origin only if the scheme, host, and port all match exactly. https://site.com and http://site.com are different origins (different scheme). https://site.com and https://api.site.com are different origins (different host). This is stricter than most people assume on first encounter.
The default: scripts can't read cross-origin responses
JavaScript running on evil.com can still send a request to bank.com — the request itself isn't blocked. What the browser blocks is letting the script on evil.com read the response. Without that protection, any site you visit could silently read your logged-in data from every other site open in your browser.
CORS as the sanctioned exception
A server that genuinely wants to let another origin read its responses sets the Access-Control-Allow-Origin header, naming which origins are trusted. The browser checks this header and only then allows the requesting page's script to read the response. This is an opt-in the server makes explicitly — it is never the browser guessing on the server's behalf.
Where this goes wrong in practice
The common CTF-relevant mistake is reflecting the request's own Origin header back as the allowed origin — effectively Access-Control-Allow-Origin: *any-site-that-asks* — sometimes combined with Access-Control-Allow-Credentials: true, which lets a malicious page read a victim's authenticated response using their own logged-in session. A wildcard * paired with credentials enabled is specifically disallowed by the spec for this reason, which is exactly why the reflect-the-origin workaround shows up instead.
Wrapping up
If a web challenge involves stealing data across two origins rather than attacking one directly, check its CORS headers before anything else — curl -I with an Origin header you control shows you exactly what the server allows back. Our Burp Suite tutorial is the tool workflow for inspecting these headers on real traffic.