The Burp Suite User Forum was discontinued on the 1st November 2024.

Burp Suite User Forum

For support requests, go to the Support Center. To discuss with other Burp users, head to our Discord page.

SUPPORT CENTER DISCORD

Erroneous identification of Cleartext submission CWE-319?

Dave | Last updated: Dec 06, 2019 05:05PM UTC

In a recent execution of a scan, Burp reported cleartext submission of a password, but the evidence in the report is merely the preceding GET request of the form which contains a password type field. The form itself has no "action" attribute and its submission is handled by a javascript which submits the form via HTTPS. Burp is erroneously assigning the url of the page containing the form to the form action. I have no record of form submission in my logs. Is this a bug, in that it is a false positive, or am I misinformed?

Mike, PortSwigger Agent | Last updated: Dec 09, 2019 02:51PM UTC