Reporting issues
Note
Reporting capabilities are only available in Burp Suite Professional.
In Burp Suite Professional, when the scanner discovers a potential vulnerability, the finding will be added to a list of issues under the Target tab, on the right-hand side of the UI:
Figure 3.149 – Issues
Issues are color-coded to indicate their severity and confidence level. An issue with a red exclamation point means it has a high severity and the confidence level is certain.
Items with a lower severity or confidence level will be low, informational, and yellow, gray, or black. These items require manual penetration testing to validate whether the vulnerability is present. For example, HTML does not specify charset is a potential vulnerability identified by the scanner. This could be an attack vector for XSS or it could be a false positive. It is up to the pentester and their level of experience to validate such an issue:
- Severity levels...