The Burp Suite User Forum was discontinued on the 1st November 2024.

Burp Suite User Forum

For support requests, go to the Support Center. To discuss with other Burp users, head to our Discord page.

SUPPORT CENTER DISCORD

Data is read from location and passed to $()

Nijish | Last updated: Jan 07, 2021 04:32AM UTC

Hi Team, Burp scan reported a vulnerability in following js statement from jquery.userTimeout.js library. Seems like a false positive, Could you please help me to understand how this can be exploited? Data is read from location and passed to $() via the following statement: var $currentReferral = $(location).attr('href'); Please suggest a fix if this is not a false positive. Thanks Nijish

Hannah, PortSwigger Agent | Last updated: Jan 07, 2021 04:46PM UTC