The Burp Suite User Forum was discontinued on the 1st November 2024.

Burp Suite User Forum

For support requests, go to the Support Center. To discuss with other Burp users, head to our Discord page.

SUPPORT CENTER DISCORD

xss -reflected

olek | Last updated: Jul 26, 2022 02:11PM UTC

hi Team I would like ask about xss reflected.I use repeater and I'm able insert xss JavaScript payload in website .But this not works when I create CSRF poc.Only when I used repeater. Burp also say my this is XSS reflected in red color. But why website owner this not accept as Valid xss ??? I'm confuse.

Ben, PortSwigger Agent | Last updated: Jul 27, 2022 04:00PM UTC

Hi Olek, You would need to discuss this with the owner of the site. We obviously have no say in whether website owners deem any vulnerabilities that you may have discovered as being valid.

olek | Last updated: Jul 27, 2022 05:46PM UTC

I don't think this is a vulnerability and the burp should not show it as red.This is second time where they refuse me this as Valid xss. Burp Show this as Valid but if poc CSRF not works this is as useless.Then I think Burp Team should removed this red illuminate from burp.Because nobody accept this as vulnerability.

olek | Last updated: Jul 29, 2022 11:57AM UTC