The Burp Suite User Forum was discontinued on the 1st November 2024.

Burp Suite User Forum

For support requests, go to the Support Center. To discuss with other Burp users, head to our Discord page.

SUPPORT CENTER DISCORD

XSS in text/javascript Content-Type

Ozgur | Last updated: Mar 23, 2018 12:16PM UTC

Burp scanner reports that on the text/javascript content type, XSS is possible with Severity: High, Confidence: Certain but I didn't find a way to prove it with a PoC. All modern browsers behave text/javascript files not as html file and as a plain text file so the injected malicious javascript doesn't work, just returned as plain text on the web browser. Is there any way to exploit this kind of vulnerabilities? Is it a misinterpretation of scanner?

PortSwigger Agent | Last updated: Mar 23, 2018 01:40PM UTC