Burp Suite User Forum

Create new post

Client-side prototype pollution in third-party libraries

MachiavelliII | Last updated: Jul 12, 2024 08:30PM UTC

Hi, I'm having trouble with the lab, after I exploited the vulnerability and tested It on myself the XSS fired with alert(1) but when I tried alert(document.cookie) the cookies didn't appear and there's no attribute prevent JavaScript from accessing the cookie It's just popup with empty alert even after I saw the solution nothing changed the same problem.

Michelle, PortSwigger Agent | Last updated: Jul 16, 2024 01:39PM UTC

Thanks for getting in touch. To help us understand what you're seeing, can we check a few details with you? When you tested with alert(document.cookie) was there any pop up at all? If you delivered the exploit to the victim, was the lab solved?

You must be an existing, logged-in customer to reply to a thread. Please email us for additional support.