The Burp Suite User Forum was discontinued on the 1st November 2024.

Burp Suite User Forum

For support requests, go to the Support Center. To discuss with other Burp users, head to our Discord page.

SUPPORT CENTER DISCORD

Cross site scripting (DOM based message)

Arslan | Last updated: Jan 14, 2020 07:07AM UTC

The application may be vulnerable to DOM-based cross-site scripting. Data is read from location and passed to jQuery() via the following statement: jQuery(location).attr('href').split("//")[1]; How is this vulnerable?

Liam, PortSwigger Agent | Last updated: Jan 14, 2020 01:43PM UTC