The Burp Suite User Forum was discontinued on the 1st November 2024.

Burp Suite User Forum

For support requests, go to the Support Center. To discuss with other Burp users, head to our Discord page.

SUPPORT CENTER DISCORD

Lab: DOM XSS in jQuery anchor href attribute sink using location.search source

Meir | Last updated: May 30, 2024 09:27PM UTC

The solution javascript:alert(document.cookie) does not work because the cookie is set as HTTPOnly

Dominyque, PortSwigger Agent | Last updated: May 31, 2024 09:06AM UTC

Hi Meir, If you follow the community solution video from Michael Sommer, does the lab then solve?

Meir | Last updated: Jun 02, 2024 06:49PM UTC