Skip to content

CVE-2023-25690 vulnerability script the false positive rate is too high #181

Description

@JaveleyQAQ

For the CVE-2023-25690 vulnerability script, the false positive rate is too high.
In default scanning mode, Burp Suite cannot distinguish static files, leading to a higher false positive rate.
For example, when accessing http://example.com/test.js?v=1 if the script's payload is added on this basis, false positive results will be generated.
image

I have not conducted in-depth research on this vulnerability, so I cannot provide detailed recommendations. However, relying solely on the "split" request response code as the basis for the vulnerability is clearly not rigorous enough.

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't workinggood first issueGood for newcomerstemplateIssue in BCheck template

    Type

    No type

    Fields

    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions