The Burp Suite User Forum was discontinued on the 1st November 2024.

Burp Suite User Forum

For support requests, go to the Support Center. To discuss with other Burp users, head to our Discord page.

SUPPORT CENTER DISCORD

XSS

colin | Last updated: Apr 04, 2021 11:48PM UTC

I'm curious ive tried injecting this into a couple places and I have no idea where this is supposed to go? Go to the exploit server(tried the url, I also tried inside the intruder tab) and paste the following code, replacing your-lab-id with your lab ID: <iframe src="https://your-lab-id.web-security-academy.net/?search=%22%3E%3Cbody%20onresize=alert(document.cookie)%3E" onload=this.style.width='100px'> Click "Store" and "Deliver exploit to victim".

Michelle, PortSwigger Agent | Last updated: Apr 05, 2021 03:32PM UTC