Burp Suite User Forum

Create new post

Cross Site Scripting - Persistent

jayaraman | Last updated: Nov 19, 2021 10:12AM UTC

Hi Team, I have a doubt, regarding XSS-Stored. Say a application has a edit feature for userinformation and there is no validation enforced. User inputs a xss script and sends the req to the server and server process the req. And if the user go to the change history page to check what changes have been done by him, which reflects the entered xss script. If i run BURP scan for this scenario will XSS-Stored be flagged?

Michelle, PortSwigger Agent | Last updated: Nov 19, 2021 02:41PM UTC

Thanks for your message. We've just replied to your email. If you're looking to understand more about how Burp detects stored input, you might find this blog post useful: https://portswigger.net/blog/improved-detection-of-stored-input

You must be an existing, logged-in customer to reply to a thread. Please email us for additional support.