Burp Suite User Forum

Create new post

XSS redirect on click button "go to exploit server"

Arthur | Last updated: Mar 23, 2021 03:52PM UTC

Hi, I'm a security information student, and I have studied through the PortSwigger academy. When exploring the lab "Lab: Reflected XSS into HTML context with all tags blocked except custom ones", a bug appens. After click in store the body of my submision, the button "go to exploit server" redirect-me to the link that I chose. the body is : <script> window.location.href = "https://my-lab-id.web-security-academy.net/?search=%3Ca2+id%3D%22a%22+onfocus%3Dalert%28document.cookie%29+tabindex%3D1+id%3Dx+autofocus%3ELINK%3C%2Fa2%3E"; </script>

Uthman, PortSwigger Agent | Last updated: Mar 23, 2021 04:57PM UTC

I have just tested the solution and it works. Are you replacing 'my-lab-id' with your lab ID? Can you share a screen recording with support@portswigger.net with the steps you are taking?

You must be an existing, logged-in customer to reply to a thread. Please email us for additional support.