The Burp Suite User Forum was discontinued on the 1st November 2024.

Burp Suite User Forum

For support requests, go to the Support Center. To discuss with other Burp users, head to our Discord page.

SUPPORT CENTER DISCORD

Lab "Reflected XSS into HTML context with all tags blocked except custom ones" cannot be validated

Lucas | Last updated: Mar 21, 2024 10:04PM UTC

Hello, I'm trying to solve the lab "Reflected XSS into HTML context with all tags blocked except custom ones" with the solution provided and I also tried other solutions on the internet but when I deliver the exploit to the victim it doesn't validate the lab. When i click on "View exploit" it works and triggers the alert(document.cookie).

Ben, PortSwigger Agent | Last updated: Mar 22, 2024 11:11AM UTC

Hi, I have just run through this lab and was able to solve it using the solution provided so it does appear to be working as expected. Are you able to provide us with a screenshot of what your exploit looks like in the exploit server? If it is easier to provide this screenshot via email then please feel free to send us an email at support@portswigger.net and we can take a look from there.

Lucas | Last updated: Mar 23, 2024 03:00PM UTC