The Burp Suite User Forum was discontinued on the 1st November 2024.

Burp Suite User Forum

For support requests, go to the Support Center. To discuss with other Burp users, head to our Discord page.

SUPPORT CENTER DISCORD

XSS Vulnerability and ClearText password

Saif | Last updated: Sep 28, 2021 05:05PM UTC

Hi Team, I have Web Application which is supported by SSL/TLS with Token mechanism and by using Burp Suite I can see password in clearText, Is this a vulnerability. I have already read the Article below. https://forum.portswigger.net/thread/password-seen-in-clear-text-on-burp-tool-d3e121c9 Can you please elaborate in more details. Also when I testing my Application URL using Burp Tool I see it adds some character in URL and due to which my application is throwing XSS error, basically I see Popup coming saying XSS POC I have no clue what does that mean. can you please explain. Thanks. Regards, Saif

Uthman, PortSwigger Agent | Last updated: Sep 29, 2021 08:53AM UTC