Burp Suite User Forum

Create new post

CVSS Score generate suite

Infinity | Last updated: Oct 10, 2023 05:39AM UTC

Hi all, this is a big task for me is that without CVSS Score in reports in our organisation the stakeholders are accepting the reports so,please provide the root cause for this CVSS Score generation by using the extension

Infinity | Last updated: Oct 10, 2023 05:40AM UTC

*not accepting

Ben, PortSwigger Agent | Last updated: Oct 10, 2023 09:42AM UTC

Hi, To confirm, Portswigger does not write or maintain the extensions that are in our BApp Store - we simply host them for the benefit of our user base. If you have any specific queries about a particular extension then our advice would be to contact the extension author on their GitHub page. As noted by a colleague of mine in response to your other forum post about this, native Burp does not use CVSS or incorporate scores when identifying vulnerabilities. If you want to include them in the vulnerability report deliverable then you would need to carry out this task yourself, likely by altering the underlying report data.

You must be an existing, logged-in customer to reply to a thread. Please email us for additional support.