The Burp Suite User Forum was discontinued on the 1st November 2024.

Burp Suite User Forum

For support requests, go to the Support Center. To discuss with other Burp users, head to our Discord page.

SUPPORT CENTER DISCORD

false positive on RXSS?

Zonduhackerone | Last updated: Apr 16, 2020 08:10PM UTC

i recently got the alert of reflected XSS with confidence certain because "vbscript:msgbox(19301293)" was injected inside a <a> tag, in the href part. I wasn't aware vbscript could be injected there. the thing is that, that payload doesn't trigger any alert and i can't seem to use that payload to achieve XSS. Is this a false positive with confidence certain or is it possible to achieve XSS like this?

Uthman, PortSwigger Agent | Last updated: Apr 20, 2020 09:49AM UTC