Burp Suite User Forum

Create new post

[BUG] Lab: DOM XSS in jQuery anchor href attribute sink using location.search source

seiku | Last updated: Jun 21, 2023 02:55PM UTC

The solution is hit the back button in "https://XXXXX.web-security-academy.net/feedback?returnPath=javascript:alert(document.cookie)" URL, exploring href unsanitized problem. Even so, the laboratory is not solved. I've seen many reports about this lab, I'm not the only one with this problem ????

Ben, PortSwigger Agent | Last updated: Jun 22, 2023 09:50AM UTC

Hi Seiku, Having just run through this particular lab I was able to solve it using the written solution (in both the embedded browser and Firefox) so it does appear to be working as expected. Are you able provide us with some screenshots of the steps you are taking to try and solve the lab?

You must be an existing, logged-in customer to reply to a thread. Please email us for additional support.