This is the source code of the Original Store challenge from zh3r0 CTF v2, feel free to use the Dockerfile to set it up and play around the null origin CORS exploit.
Original Store v2
Hi , some bad people stole our cars the last time so we made our security better this time, no one can break this. Our store is now at <challenge_link> while our car review page is at <admin_bot_link>