
HTML Injection (CWE-79)CVSS 2.5€0
HTML Injection in DAST Trial Request Form Confirmation Email – PortSwigger
zorixu
Disclosed on HackerOne · February 26, 2026
Publicly disclosed report · by zorixu
View original on HackerOneSummary
The DAST trial request form at https://portswigger.net/burp/dast/trial is vulnerable to HTML injection through the "First Name" field. User-supplied input is not properly sanitized before being inserted into confirmation emails, allowing attackers to inject arbitrary HTML content that gets rendered in the victim's email client. This vulnerability can be exploited to conduct sophisticated phishing attacks that appear to originate from PortSwigger's legitimate email infrastructure.
Steps to Reproduce
- Navigate to
https://portswigger.net/burp/dast/trial - Locate the "Request a tailored demo" form
- Fill in all required fields with legitimate data
- In the "First Name" field, insert the following payload: