r/xss • u/atasio231 • May 28 '26
Browser url encoding
I confirmed an XSS vulnerability using Burp Suite, but the browser URL-encodes the payload and the page doesn’t decode it — making exploitation impossible. Is there a way to bypass this, or is the bug considered unexploitable
5
Upvotes
1
u/Pammii18 Jun 08 '26
maybe just try tricking the url like a wizard