The Burp Suite User Forum was discontinued on the 1st November 2024.

Burp Suite User Forum

For support requests, go to the Support Center. To discuss with other Burp users, head to our Discord page.

SUPPORT CENTER DISCORD

About Audit results Cross-site scripting (reflected)

hideki | Last updated: Aug 31, 2022 12:41AM UTC

I have detected reliable cross-site scripting in audit, but I need help because I have doubts about the correct results. The results indicate that the script is reflective. However, the content type is javascript, so the browser recognizes that this injected script is not executed. Can you please let me know if I am wrong in my perception? Is it just a false positive? ---------------------- Content-Type: text/javascript; charset=utf-8 ~~ alert(1)// ----------------------

Michelle, PortSwigger Agent | Last updated: Aug 31, 2022 07:27AM UTC