The Burp Suite User Forum was discontinued on the 1st November 2024.

Burp Suite User Forum

For support requests, go to the Support Center. To discuss with other Burp users, head to our Discord page.

SUPPORT CENTER DISCORD

Web Cache poisoning: URL normalization lab can be solved as basic XSS lab

Aetius | Last updated: Jan 09, 2023 10:05PM UTC

Hello, Wanted to inform you that when you submit this URL payload: `https://YOUR-LAB-ID.web-security-academy.net/post/comment/confirmation?test=g&postId=%22%3E%3C/a%3E%3Cscript%3Ealert(1)%3C/script%3E` It validates directly the challenge without even needing to poison the cache, To me this behavior seems like a basic XSS challenge and I don't think it was intended to bypass the steps of the solution like this.

Hannah, PortSwigger Agent | Last updated: Jan 11, 2023 10:27AM UTC