Burp Suite User Forum

Create new post

Lab: DOM XSS in jQuery anchor href attribute sink using location.search source

Meir | Last updated: May 30, 2024 09:27PM UTC

The solution javascript:alert(document.cookie) does not work because the cookie is set as HTTPOnly

Dominyque, PortSwigger Agent | Last updated: May 31, 2024 09:06AM UTC

Hi Meir, If you follow the community solution video from Michael Sommer, does the lab then solve?

Meir | Last updated: Jun 02, 2024 06:49PM UTC

Now the lab was changed to "solved" when I used the same solution that previously didn't work. odd.

You must be an existing, logged-in customer to reply to a thread. Please email us for additional support.