The Burp Suite User Forum was discontinued on the 1st November 2024.

Burp Suite User Forum

For support requests, go to the Support Center. To discuss with other Burp users, head to our Discord page.

SUPPORT CENTER DISCORD

Wrong statement in XSS learning material?

Sid | Last updated: Nov 30, 2022 09:46AM UTC

In the last lines of chapter 2 of Stored XSS section (Impact of stored XSS attacks) it says "In contrast, if the XSS is stored, then the user is guaranteed to be logged in at the time they encounter the exploit." Is this really true? What if the user views a malicious, public forum post while not authenticated?

Hannah, PortSwigger Agent | Last updated: Dec 01, 2022 01:30PM UTC