The Burp Suite User Forum was discontinued on the 1st November 2024.

Burp Suite User Forum

For support requests, go to the Support Center. To discuss with other Burp users, head to our Discord page.

SUPPORT CENTER DISCORD

[BUG] Lab: DOM XSS in jQuery anchor href attribute sink using location.search source

seiku | Last updated: Jun 21, 2023 02:55PM UTC

The solution is hit the back button in "https://XXXXX.web-security-academy.net/feedback?returnPath=javascript:alert(document.cookie)" URL, exploring href unsanitized problem. Even so, the laboratory is not solved. I've seen many reports about this lab, I'm not the only one with this problem ????

Ben, PortSwigger Agent | Last updated: Jun 22, 2023 09:50AM UTC