CORS is not related to security enhancement, but to weaken it (but only under certain conditions with the permission of the server).
If you want to access something from another server in an AJAX request without CORS, you are not allowed because of "security" (the same origin policy), and this is its end *. With CORS, another server can give permission to reduce this security barrier.
<sub> * Except for hacks such as JSONP, but this also requires permission from the Sub server>
rjmunro Mar 26 '12 at 11:30 2012-03-26 11:30
source share