The Burp Suite User Forum was discontinued on the 1st November 2024.

Burp Suite User Forum

For support requests, go to the Support Center. To discuss with other Burp users, head to our Discord page.

SUPPORT CENTER DISCORD

Lab: DOM XSS in document.write sink using source location.search inside a select element

Laur | Last updated: Nov 14, 2020 01:37PM UTC

I get the xss pop-up but the lab does not report it solved. I crafted the URL with the storeId query parameter and inserted javascript payload using alert function which pops "1". Can you guys take a look at that?

Ben, PortSwigger Agent | Last updated: Nov 16, 2020 02:22PM UTC