Burp Suite User Forum

Create new post

Cross-site scripting (reflected) Change?

Ryan | Last updated: Jan 23, 2017 09:11PM UTC

Cross-site scripting (reflected) now shows as an informational instead of a high finding after the .16 update. Is that supposed to be the case?

PortSwigger Agent | Last updated: Jan 24, 2017 09:22AM UTC

Some XSS issues are reported as informational if there is a significant caveat (such as MIME type or insertion point type) that affects exploitability. This should be clearly described in the issue detail. This has always been the case and no relevant changes were made in a recent release.

You must be an existing, logged-in customer to reply to a thread. Please email us for additional support.