The Burp Suite User Forum was discontinued on the 1st November 2024.

Burp Suite User Forum

For support requests, go to the Support Center. To discuss with other Burp users, head to our Discord page.

SUPPORT CENTER DISCORD

BURP-Suite unable to detect HTML Injection (XSS) in my scan

David | Last updated: Jul 02, 2021 04:10AM UTC

Hi, One of my customers reported that he was able to inject a html tag <i>Italic</i> in one of the fields in our app and the html was reflected. I verified what he said and indeed that was true. What I did was I recorded the steps by navigating to the page in question and inserted <i>Italic</i> in one of the fields, and yes, the html tag was rendered. But when I ran a scan using the steps I recorded earlier and the vulnerability was not reported. It seems this vulnerability is happening in many places in our app and we would like the tool to be able to pick up all these issues. Do you think this is a bug in your tool? Any help or advise would be greatly appreciated. Thanks, Dave

Michelle, PortSwigger Agent | Last updated: Jul 02, 2021 11:12AM UTC