Burp Suite User Forum

Create new post

Autocomplete/Autofill enabled

Srinivashan | Last updated: Feb 18, 2020 10:54AM UTC

Hi, I have done a security testing in Burp Suite, while doing we have faced the below issue for our application. issue description : "It was noted during the assessment that auto-complete feature was enabled on certain forms in which personal information was being input for processing. When a new name and password is entered in a form and the form is submitted, the browser confirms if the password should be saved. Double-clicking in an input field was revealing the information(s) previously put into those fields." By scanning using Burp suite pro, I have retrieved the above issue but i couldn't reproduce manually using intercepts. Can you help me out in identifying the issue manually?

Michelle, PortSwigger Agent | Last updated: Feb 18, 2020 11:43AM UTC

Could you tell us a bit more about what you have tried so far when attempting to manually reproduce the issue, please? There are many reasons that reproduction can be non-trivial. For example, the request in the issue description may contain a session cookie, that has expired by the time you try to reproduce. The Burp scanning engine is one of the most accurate available, but false positives can occur with any scanner. If you can provide a screenshot of the request and response from the issue via email to support@portswigger.net, we may be able to provide further advice based on that.

You must be an existing, logged-in customer to reply to a thread. Please email us for additional support.