The Burp Suite User Forum was discontinued on the 1st November 2024.

Burp Suite User Forum

For support requests, go to the Support Center. To discuss with other Burp users, head to our Discord page.

SUPPORT CENTER DISCORD

SQL injection vulnerability in WHERE clause allowing retrieval of hidden data

Daniel | Last updated: Oct 21, 2023 06:48PM UTC

I believe this sql injection vulnerability can be solved without burp. e.g., just replaying the request with the payload via the browser: https//....web-security-academy.net/filter?category=Tech+gifts%27--%20 However, the status did not change to 'solved'. It would be nice, if you can fix it.

Ben, PortSwigger Agent | Last updated: Oct 23, 2023 09:48AM UTC