Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Better severity rating #20

Open
wants to merge 2 commits into
base: master
Choose a base branch
from
Open

Better severity rating #20

wants to merge 2 commits into from

Conversation

shelld3v
Copy link
Contributor

@shelld3v shelld3v commented Feb 2, 2021

My burp is getting flooded by shitty false positives, so submit this. Feel free to ask me for adjusting

@shelld3v
Copy link
Contributor Author

shelld3v commented Feb 2, 2021

Also, how reflections in headers can be a possible XSS?

@elkokc
Copy link
Owner

elkokc commented Feb 9, 2021

First of all, thank you for using our plugin after all this time.
Technologies are rapidly evolving, but bugs remain. I think "XSS in Headers" in this case related to CRLF injection. The are many cases and various techniques , when user can manipulate with this type of vulnerability in order to escalate it to XSS or use for web cache poisoning. I am agree with you that these days It's hardly even face with CRLF injection, but who knows?
Thank you for your Pull-Request. Wouldn't it be better to make this option adjustable? In that case user could easily switch, depending on their needs.

@shelld3v
Copy link
Contributor Author

shelld3v commented Feb 9, 2021

I just only changed the "XSS in header" severity to "Unlikely", didn't remove it.

Wouldn't it be better to make this option adjustable? In that case user could easily switch, depending on their needs.

I don't have too much time and skills to can do that! Can u do it?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants