Burp Suite User Forum

Create new post

Academy

Kim | Last updated: Mar 08, 2020 09:04PM UTC

Hi I tried out, the following piece on the third XSS lab: <lala onfocus="alert(document.cookie)" tabindex="1" id="x" autofocus>test</lala> or URL encoded, like: %3Clala%20onfocus%3D%22alert%28document.cookie%29%22%20tabindex%3D%221%22%20id%3D%22x%22%20autofocus%3Etest%3C%2Flala%3E Which actually shows an empty alert box (Did this in FF). But the lab isn't marked as solved. Am I doing this wrong or is this a bug in the academy? /Kim

Ben, PortSwigger Agent | Last updated: Mar 09, 2020 09:18AM UTC

Hi Kim, Can you just confirm the name of the lab that you are having issues with? Is it "Reflected XSS into HTML context with all tags blocked except custom ones"?

You must be an existing, logged-in customer to reply to a thread. Please email us for additional support.