The Burp Suite User Forum was discontinued on the 1st November 2024.

Burp Suite User Forum

For support requests, go to the Support Center. To discuss with other Burp users, head to our Discord page.

SUPPORT CENTER DISCORD

Dom based XSS - how to exploit

Chhavi | Last updated: May 08, 2020 06:03AM UTC

While running a scan, DOM based XSS was reported. I dont know how to exploit this, can you help. Here are the details: Issue details: The application may be vulnerable to DOM-based cross-site scripting. Data is read from input.value and passed to element.innerHTML. Nothing has been highlighted in request or response Dynamic Analysis tab shows following: Data is read from input.value and passed to element.innerHTML. The following value was injected into the source: <span class='icon-comment'></span> The previous value reached the sink as: a4zvuzavz4%2527%2522`'"/a4zvuzavz4/><a4zvuzavz4/\>vmdowq5zz9&

Uthman, PortSwigger Agent | Last updated: May 08, 2020 08:45AM UTC