The Burp Suite User Forum was discontinued on the 1st November 2024.

Burp Suite User Forum

For support requests, go to the Support Center. To discuss with other Burp users, head to our Discord page.

SUPPORT CENTER DISCORD

Do not validate the XSS lab

SpXctrum | Last updated: Feb 08, 2023 11:03AM UTC

Hello the Lab: "Stored XSS into onclick event with angle brackets and double quotes HTML-encoded and single quotes and backslash escaped" do not validate even with correct payloads. It trigger the alert() but nothing happens. My payloads : - http:#');alert();//mine - http://foo?'-alert(1)-'

SpXctrum | Last updated: Feb 08, 2023 12:00PM UTC