Burp Suite User Forum

Create new post

Web Security Academy - Reflected XSS into attribute with angle brackets HTML-encoded: Additional solutions

CptT3fl0n | Last updated: Jan 22, 2021 03:13PM UTC

Hi together, I have some feedback for the Web Security Academy :) 1. I couldn't find where to put feedback for the labs. So I hope I'm right here. 2. In the "Reflected XSS into attribute with angle brackets HTML-encoded" (https://portswigger.net/web-security/cross-site-scripting/contexts/lab-attribute-angle-brackets-html-encoded) lab it should also accept different solutions as `onmouseover` EventHandler. I tried it with the onblur handler (Test" onblur=alert(1);") as payload and it didn't solved the challenge, what was really confusing for me. Perhaps there are other eventhandlers that also do not work. Not tested it. Maybe you can fix that. :) Best Regards

You must be an existing, logged-in customer to reply to a thread. Please email us for additional support.