Burp Suite User Forum

Create new post

XSS Vulnerability and ClearText password

Saif | Last updated: Sep 28, 2021 05:05PM UTC

Hi Team, I have Web Application which is supported by SSL/TLS with Token mechanism and by using Burp Suite I can see password in clearText, Is this a vulnerability. I have already read the Article below. https://forum.portswigger.net/thread/password-seen-in-clear-text-on-burp-tool-d3e121c9 Can you please elaborate in more details. Also when I testing my Application URL using Burp Tool I see it adds some character in URL and due to which my application is throwing XSS error, basically I see Popup coming saying XSS POC I have no clue what does that mean. can you please explain. Thanks. Regards, Saif

Uthman, PortSwigger Agent | Last updated: Sep 29, 2021 08:53AM UTC

Hi Saif,

We do not offer consulting services so cannot interpret your scan results for you, unfortunately. In terms of the scan issue itself, you can find out more information here.

The scanner is adding characters or 'payloads' to your URL as part of the scan check to see whether the issue exists. You can find out more information on the scanner here. The Auditing section will help you understand this better.

Please take a look at the free resources in our Web Security Academy to understand XSS better:

You must be an existing, logged-in customer to reply to a thread. Please email us for additional support.