The Burp Suite User Forum was discontinued on the 1st November 2024.

Burp Suite User Forum

For support requests, go to the Support Center. To discuss with other Burp users, head to our Discord page.

SUPPORT CENTER DISCORD

Lab: DOM XSS via client-side prototype pollution (not working)

Tuan | Last updated: Oct 29, 2024 10:24AM UTC

Here is the payload that I used: https://MY-LAB-ID.web-security-academy.net/?__proto__[transport_url]=data:,alert(1); It popped an XSS alert(1) but the lab is still not solved. Please help!

Tuan | Last updated: Oct 29, 2024 10:46AM UTC

I actually solved the above lab, but Lab: Client-side prototype pollution via browser APIs also making same mistake.

Dominyque, PortSwigger Agent | Last updated: Oct 29, 2024 11:10AM UTC