The Burp Suite User Forum was discontinued on the 1st November 2024.

Burp Suite User Forum

For support requests, go to the Support Center. To discuss with other Burp users, head to our Discord page.

SUPPORT CENTER DISCORD

Cross Site Scripting

Yee, | Last updated: Feb 09, 2021 12:29AM UTC

Hi, we are using the Burp professional version. We are doing cross site scripting testing on our application. There is one page where we can create an object with java script in the input values (ex: <script> alert(1) </script> ). The javascript has executed and this is clearly an issue with javascript injection. When we scan the site and on this particular page, the Burp didn't return a Cross Site Scripting issue with our application. Anyone has encountered this before. Any additional configuration need to do. We are using the out of box setting for scan. Thank you!

Michelle, PortSwigger Agent | Last updated: Feb 09, 2021 03:28PM UTC