Burp Suite User Forum

Create new post

Lab: Stored XSS into anchor href attribute with double quotes HTML-encoded

Sebastião | Last updated: Apr 13, 2020 04:44PM UTC

Hi, Please, I need help, The steps do not work.

Uthman, PortSwigger Agent | Last updated: Apr 14, 2020 09:25AM UTC

Hi, I have just tested the lab and it works. Can you please provide more information about the exact steps you are following (along with screenshots)? What browser are you using?

Khoa | Last updated: Jun 23, 2020 04:14AM UTC

javascript:alert(1) in the Website section didn't solve the lab, however manually clicks on the name , XSS is triggered (tested on both Firefox and Chrome). Any advices?

Uthman, PortSwigger Agent | Last updated: Jun 23, 2020 08:14AM UTC

I just tested the lab again and it still works. Can you please try the below? 1. Select View post on any post 2. Type some information into the Comment, Name, and Email fields 3. Type javascript:alert(1) into the Website field The lab should complete after that. If it still does not, can you please send us a video of the steps you are following? support@portswigger.net

You must be an existing, logged-in customer to reply to a thread. Please email us for additional support.