Burp Suite User Forum

Create new post

'Credit Card numbers disclosed' finding false positive

Tim | Last updated: Apr 19, 2024 12:07AM UTC

Hi there, Using Burp 2024.2.1.5. As part of passive scanning a 'Credit Card numbers disclosed' finding was reported: Issue detail: The following credit card number was disclosed in the response: 4328581774284737 But this number is not in the response and the highlighted part of the response is: ight":true},{"_uid Not sure what's going on there, but just thought I'd let you know. Cheers

Syed, PortSwigger Agent | Last updated: Apr 19, 2024 07:53AM UTC

Hi Tim,

Thank you for your message!

Burp has a scan check that tests for credit card numbers and since that number fits that pattern, Burp flagged it. However, I am curious if that number is not in the response, why did Burp report it. I would appreciate it if you could share a few screenshots for this reported vulnerability including the request/response and the advisory to our support email - support@portswigger.net

Thank you!

You must be an existing, logged-in customer to reply to a thread. Please email us for additional support.