The Burp Suite User Forum was discontinued on the 1st November 2024.

Burp Suite User Forum

For support requests, go to the Support Center. To discuss with other Burp users, head to our Discord page.

SUPPORT CENTER DISCORD

CSRF in POST request. Proxy only shows GET.

Ryan | Last updated: Nov 07, 2016 03:28PM UTC

Found an interesting issue. A recent scan gave a CSRF finding in a POST. Going to the HTTP history tab multiple GETs to the same resource that was identified in the finding but no POSTs were found. How am I able to to create a PoC if the vulnerable transaction is not listed in the history tab? Also, any ideas on why there are POSTs finding issues but not listed in history? Thanks,

PortSwigger Agent | Last updated: Nov 07, 2016 03:29PM UTC