Lab: Stored XSS into onclick event with angle brackets and double HTML

Cyn | Last updated: Aug 02, 2019 06:44PM UTC

Hi! I've done the exercise https://portswigger.net/web-security/cross-site-scripting/contexts/lab-onclick-event-angle-brackets-double-quotes-html-encoded-single-quotes-backslash-escaped but it was not marked as resolved... Also, I've made all the steps described in the "Solution" tab and it follow shown as not solved ... Can you help me? P.S: Sorry for my english

Burp User | Last updated: Aug 04, 2019 12:37PM UTC

Same problem here. I completed the lab but it is still labeled "Not solved". Thank you

Liam, PortSwigger Agent | Last updated: Aug 05, 2019 08:53AM UTC

Thanks for this report. We've confirmed this is broken and we'll get it fixed. In the meantime there is another solution that will solve the lab.

