Cross-site scripting
XSS · A type of flaw where an attacker can place their own script in a web page and run it in the browsers of other users who open that page.
- 01
Why it matters
With XSS an attacker can hijack the victim's session, show a fake sign-in form on the page or act on the user's behalf. Anywhere user input is displayed, such as comments, search and profile fields, is at risk. The fix is encoding input correctly for where it is displayed, plus a content security policy.
- 02
Example
Text entered in a forum profile field is printed onto the page as it is. An attacker puts a script there; every moderator who opens the profile unknowingly sends their session details to the attacker.
- 03
Common mistake
Trying to defend by filtering a few characters. Filters can be bypassed with other encodings; the right approach is context-aware output encoding and safe, ready-made templating tools.
- 04
Related terms
Related services and guides
Let's talk about your project.
Tell us what you need; we will define the scope together.