The Burp Suite User Forum was discontinued on the 1st November 2024.

Burp Suite User Forum

For support requests, go to the Support Center. To discuss with other Burp users, head to our Discord page.

SUPPORT CENTER DISCORD

Reflected XSS in a JavaScript URL with some characters blocked - unintentional xss

mrkl | Last updated: Jan 12, 2023 08:45PM UTC

Hi team, not sure if labs are built with only one particular and intended vulnerability per lab but in "Reflected XSS in a JavaScript URL with some characters blocked" there is other xss not related to the theme/scope of the lab. https://[labId]/post/comment/confirmation?postId=31xx"><img+src%3dx+onerror%3dalert(1337)>1

Michelle, PortSwigger Agent | Last updated: Jan 13, 2023 10:12AM UTC

The labs can sometimes have alternate solutions. Were you able to solve the lab using your alternative solution? If so, can you confirm the steps you were taking?

mrkl | Last updated: Jan 20, 2023 11:34AM UTC

I can trigger alert function (see the link with payload in the original post) but this does not solve lab. I would not call it an alternate solution because the level of the lab is rated Expert and the xss I found is beginner/easy level.

Michelle, PortSwigger Agent | Last updated: Jan 20, 2023 04:08PM UTC