The Burp Suite User Forum was discontinued on the 1st November 2024.

Burp Suite User Forum

For support requests, go to the Support Center. To discuss with other Burp users, head to our Discord page.

SUPPORT CENTER DISCORD

Regarding brup automatic scanner result ,Can I take it false positive ?

Mohamed | Last updated: Sep 29, 2023 05:05AM UTC

Issue : The application may be vulnerable to DOM-based link manipulation. Data is read from location.pathname and passed to element.setAttribute.href. The previous value reached the sink as: #​ Scenario : At some instance reported issue `#` is used as a placeholder in the href attribute to create client-side actions is not inherently insecure. It's often used to create buttons or links that perform JavaScript actions without navigating to a new page. This is a legitimate and common approach in web development. And in other cases, it was used to locate a component by its name and add it to the right element with the right ID. All the above, code instances are free from direct user interaction and there is no dynamic data manipulation. Can I conclude reported issue is false positive ? Regards, Mohamed

Dominyque, PortSwigger Agent | Last updated: Sep 29, 2023 07:11AM UTC