The Burp Suite User Forum was discontinued on the 1st November 2024.

Burp Suite User Forum

For support requests, go to the Support Center. To discuss with other Burp users, head to our Discord page.

SUPPORT CENTER DISCORD

Lab can be completed without performing all the required tasks.

Anurag | Last updated: Dec 26, 2022 02:14PM UTC

Hi, there is an issue in the following lab: https://portswigger.net/web-security/sql-injection/lab-retrieve-hidden-data The lab objective is to perform an SQL injection attack that causes the application to display details of all products in *any* category, *both* released and unreleased. However, the lab gets completed even if we don't comment out the rest of the SQL query to show the unreleased products and complete just the first requirement, i.e. to display details of all products in any category. Proper validation is missing in the backend to check whether the lab is being completed in the intended way or not. Proof Of Concept: https://LAB-LINK-HERE/filter?category=CATEGORY-NAME%27%20OR%20%27a%27=%27a

Liam, PortSwigger Agent | Last updated: Dec 28, 2022 12:22PM UTC

Thanks for this report, Anurag. We'll investigate and get back to you.

Michelle, PortSwigger Agent | Last updated: Jan 03, 2023 02:53PM UTC