Burp Suite User Forum

Create new post

false positive on RXSS?

Zonduhackerone | Last updated: Apr 16, 2020 08:10PM UTC

i recently got the alert of reflected XSS with confidence certain because "vbscript:msgbox(19301293)" was injected inside a <a> tag, in the href part. I wasn't aware vbscript could be injected there. the thing is that, that payload doesn't trigger any alert and i can't seem to use that payload to achieve XSS. Is this a false positive with confidence certain or is it possible to achieve XSS like this?

Uthman, PortSwigger Agent | Last updated: Apr 20, 2020 09:49AM UTC

Have you tried reproducing this in IE 9? Can you share the full Issue detail, request and response to us via email? support@portswigger.net

You must be an existing, logged-in customer to reply to a thread. Please email us for additional support.