Creating new issues via the Add & Track Custom Issues extension
Though Burp Suite provides a listing of many security vulnerabilities commonly found in web applications, occasionally you will identify an issue and need to create a custom scan finding. This can be done using the Add & Track Custom Issues extension.
Note
This plugin requires the Burp Suite Professional edition.
Getting ready
Using the OWASP Mutillidae II application, we will add the Add & Track Custom Issues extension, create steps revealing a finding, and then use the extension to create a custom issue.
How to do it...
- Switch to the Burp Suite Extension tab. Go to the BApp Store subtab and find the plugin labeled Add & Track Custom Issues. Click the Install button:

Figure 10.45 – Add & Track Custom Issues extension
- Ensure the extension is loaded and enabled in the Extensions | Installed | Burp extensions section:
...