The Burp Suite User Forum was discontinued on the 1st November 2024.

Burp Suite User Forum

For support requests, go to the Support Center. To discuss with other Burp users, head to our Discord page.

SUPPORT CENTER DISCORD

LAB "Reflected XSS into a template literal with angle brackets, single, double quotes, backslash and backticks Unicode-escaped" is not getting marked as SOLVED

Aakash | Last updated: Oct 04, 2024 01:32PM UTC

I am injecting below XSS payload and getting the popup with domain mentioned in it. https://0a36008e04cdc01a80cec72700990053.web-security-academy.net/?search=test%20${alert(document.domain)} Also, tried with test%20${alert()}, test%20${alert(1)} as well. Still not getting it solved.

Ben, PortSwigger Agent | Last updated: Oct 07, 2024 08:41AM UTC

Hi Aakash, I have just run through this particular lab and been able to solve it using the suggested payload of ${alert(1)}. Have you tried this? If so, which browser are you using?

Aakash | Last updated: Oct 08, 2024 08:02PM UTC