The Burp Suite User Forum was discontinued on the 1st November 2024.

Burp Suite User Forum

For support requests, go to the Support Center. To discuss with other Burp users, head to our Discord page.

SUPPORT CENTER DISCORD

Stored XSS into anchor href attribute with double quotes HTML-encoded is not recognizing an XSS

saiteja | Last updated: Nov 08, 2020 01:04PM UTC

I have done the following submit a comment that calls the alert function when the comment author name is clicked. I have used the following payload in the website field of the form: javascript:alert(1)

Uthman, PortSwigger Agent | Last updated: Nov 09, 2020 09:39AM UTC