The Burp Suite User Forum was discontinued on the 1st November 2024.

Burp Suite User Forum

For support requests, go to the Support Center. To discuss with other Burp users, head to our Discord page.

SUPPORT CENTER DISCORD

DOM based Link Manipulation false positive

Cyrus | Last updated: Mar 23, 2023 02:35PM UTC

Portswigger, We currently use the enterprise version of burpsuite, currently we have a method of determining if DOM based Link manipulation are false positives or not, we would like to receive some feedback from a portswigger agent to determine if these link manipulation vulnerabilities are true findings or not. Issue detail The application may be vulnerable to reflected DOM-based link manipulation. The value of the title request parameter is copied into a JavaScript string literal. The payload gwfspvkwr8 was submitted in the title parameter. The string containing the payload is then passed to anchor.href. Is the anchor.ref sink in the context of DOM based Link Manipulation considered a false positive? If not, how could we further test this sink to determine confidence of this specific finding. Thank you

Alex, PortSwigger Agent | Last updated: Mar 24, 2023 08:50AM UTC