The Burp Suite User Forum was discontinued on the 1st November 2024.

Burp Suite User Forum

For support requests, go to the Support Center. To discuss with other Burp users, head to our Discord page.

SUPPORT CENTER DISCORD

LAB: Reflected XSS with event handlers and href attributes blocked

Dray | Last updated: Dec 27, 2021 07:15PM UTC

Hi, I'm facing with an issue on this lab. I'm visiting this site which contains the XSS payload which creates an svg-animated anchor: https://MY-WEBAPP-ID.web-security-academy.net/?search=%3Csvg%3E%3Ca%3E%3Canimate+attributeName%3Dhref+values%3Djavascript%3Aalert%281%29+%2F%3E%3Ctext+x%3D20+y%3D150%3EClick me%3C%2Ftext%3E%3C%2Fa%3E But the bot does not seem to click or be triggered by the "Click" string as mentionned in the lab description. Thus, I'd like to understand how I could validate this lab ? I tested the same payload on Chrome(Brave) and Firefox but same result, it's not triggered. Thanks for the help !

Liam, PortSwigger Agent | Last updated: Jan 04, 2022 09:12AM UTC

Thanks for your message. The lab is passing in our testing. Are you still encountering this issue?

Bhupendra | Last updated: Jan 18, 2022 11:14AM UTC

Yes , same problem here ,<b>not working for me too.</b>

Liam, PortSwigger Agent | Last updated: Jan 18, 2022 12:57PM UTC