Burp Suite User Forum

Create new post

Solution is outdated for "Lab: Reflected XSS with some SVG markup allowed"

Roman | Last updated: Aug 08, 2021 04:08PM UTC

Hello! I've been found out that the intended solution is outdated in steps 7-9 and 12-14. The reason for this is that the <animateTransform> tag is no longer in XSS cheat sheet page. So that with some svg-specivit events. Eventhoug all svg-related events can be easily found on the internet and created a simple list for intruder, the <animateTransform> is crucial.

Hannah, PortSwigger Agent | Last updated: Aug 11, 2021 02:08PM UTC

Hi We've checked the 2021 XSS cheat sheet, and it does contain the animatetransform tag. We also completed the lab following the exact methods described in the lab description and encountered no issues.

You must be an existing, logged-in customer to reply to a thread. Please email us for additional support.