The Burp Suite User Forum was discontinued on the 1st November 2024.

Burp Suite User Forum

For support requests, go to the Support Center. To discuss with other Burp users, head to our Discord page.

SUPPORT CENTER DISCORD

Strange XSS false positives in scanning.

Ash | Last updated: Mar 17, 2019 01:50AM UTC

I was trying to scan an application with Burp. The scanner found around 20 XSS and in the scanner, the request and how the payload was reflected in the response was clear in the response tab. However, when trying to manually verify the exploit (the the same payload to the same URL) the payload was HTML encoded. How comes that it in clear in the "Response" tab and encoded in the page?

PortSwigger Agent | Last updated: Mar 18, 2019 02:50PM UTC

Hi Ash Please could you give us a bit more information. What requests where used? What were the responses? Kind regards Gareth

PortSwigger Agent | Last updated: Mar 18, 2019 03:40PM UTC