The Burp Suite User Forum was discontinued on the 1st November 2024.

Burp Suite User Forum

For support requests, go to the Support Center. To discuss with other Burp users, head to our Discord page.

SUPPORT CENTER DISCORD

Unintended Solving Via Known DOMPurify XSS Vulnerability in Cache Poisoning Lab

Alexander | Last updated: May 08, 2023 10:03PM UTC

Hi, for this lab: https://portswigger.net/web-security/web-cache-poisoning/exploiting-design-flaws/lab-web-cache-poisoning-targeted-using-an-unknown-header. The comment section uses DOMPurify 2.0.15, and can be exploited by known XSS (https://portswigger.net/research/bypassing-dompurify-again-with-mutation-xss) to alert document.cookie, and thus solving the lab without actually doing any cache poisoning exploit. Would it be better to remove this possibility in order to narrow down cache poisoning as only solution? This might be a stupid suggestion since we are getting solutions for these labs for easy "solving", but just wanted to point that out.

Michelle, PortSwigger Agent | Last updated: May 09, 2023 01:02PM UTC