The Burp Suite User Forum will be discontinued on the 1st November 2024.

Burp Suite User Forum

For support requests, go to the Support Centre. To discuss with other Burp users, head to our Discord page.

SUPPORT CENTRE DISCORD

Create new post

LAB "Reflected XSS into a template literal with angle brackets, single, double quotes, backslash and backticks Unicode-escaped" is not getting marked as SOLVED

Aakash | Last updated: Oct 04, 2024 01:32PM UTC

I am injecting below XSS payload and getting the popup with domain mentioned in it. https://0a36008e04cdc01a80cec72700990053.web-security-academy.net/?search=test%20${alert(document.domain)} Also, tried with test%20${alert()}, test%20${alert(1)} as well. Still not getting it solved.

Ben, PortSwigger Agent | Last updated: Oct 07, 2024 08:41AM UTC

Hi Aakash, I have just run through this particular lab and been able to solve it using the suggested payload of ${alert(1)}. Have you tried this? If so, which browser are you using?

Aakash | Last updated: Oct 08, 2024 08:02PM UTC

It has been solved. Thanks

You must be an existing, logged-in customer to reply to a thread. Please email us for additional support.