The Burp Suite User Forum was discontinued on the 1st November 2024.

Burp Suite User Forum

For support requests, go to the Support Center. To discuss with other Burp users, head to our Discord page.

SUPPORT CENTER DISCORD

Confidential/sensitive information accessible for non-legitimate users

BOURASS | Last updated: Mar 03, 2021 04:48PM UTC

Hello, During a POC we are running using BurpSuite Enterprise web application scanner, we encountered an issue (not much a bug, but more a security weakness) : as it is possible to provide credentials for authenticated scans in the "Scan Configuration" feature, any user that has access rights on the scan configurations can download all scan configurations and access credentials within, which are in plain text. Hope you can help us with this issue. Thank you. Taha BOURASS

Michelle, PortSwigger Agent | Last updated: Mar 04, 2021 05:11PM UTC