The Burp Suite User Forum was discontinued on the 1st November 2024.

Burp Suite User Forum

For support requests, go to the Support Center. To discuss with other Burp users, head to our Discord page.

SUPPORT CENTER DISCORD

False Positive Tag Rendering in Burpsuite

tanknight | Last updated: Aug 31, 2024 12:32AM UTC

I was testing on a website, and found an Reflected XSS, but it seems it's only working if i open request on browser (with burpsuite link). When i open it manually to the browser, the XSS doesn't work Request: GET /simperpus/index.php?keywords=TESTINGWKWK"><img/src/onerror=prompt(1)>&search=search Burpsuite Response: <a href="index.php?resultXML=true&keywords=TESTINGWKWK"><img/src/onerror=prompt(1)>&search=search" Real Website Response: <a href="index.php?JSONLD=true&amp;keywords=TESTINGWKWK%22%3E%3Cimg/src/onerror=prompt(1)%3E&amp;search=search"

Hannah, PortSwigger Agent | Last updated: Sep 03, 2024 04:28PM UTC