In previous versions of Burp, the Scanner tool contained a Results tab in which all discovered issues were displayed. These issues have now been moved into Burp's main site map, within the Target tool. The site map now contains a consolidated view of all the contents and issues that have been discovered about target applications.
Get help and join the community discussions at the Burp Suite Support Center.
This release adds a new scan check for external service interaction and out-of-band resource load via injected XML doctype tags containing entity parameters.
Burp Scanner now modifies XML in requests to inject a doctype tag that defines an XML entity parameter that references a Burp Collaborator URL, and reports an appropriate issue based on any observed interactions (DNS or HTTP) that reach the Burp Collaborator server.