The Burp Suite User Forum was discontinued on the 1st November 2024.

Burp Suite User Forum

For support requests, go to the Support Center. To discuss with other Burp users, head to our Discord page.

SUPPORT CENTER DISCORD

Cross Site Scripting - Persistent

jayaraman | Last updated: Nov 19, 2021 10:12AM UTC

Hi Team, I have a doubt, regarding XSS-Stored. Say a application has a edit feature for userinformation and there is no validation enforced. User inputs a xss script and sends the req to the server and server process the req. And if the user go to the change history page to check what changes have been done by him, which reflects the entered xss script. If i run BURP scan for this scenario will XSS-Stored be flagged?

Michelle, PortSwigger Agent | Last updated: Nov 19, 2021 02:41PM UTC