DFIELDSOLUTIONS

Security

GlossaryCross-site scripting (XSS)

An attack that injects hostile JavaScript into a page other people view — the browser runs the attacker's code with the victim's session.

The page is trusted; anything that lands on it inherits that trust. If a comment, a profile field or a URL parameter reaches the HTML unescaped, the attacker's script runs in every visitor's browser — reading session tokens, keylogging, acting as the user. Stored, reflected and DOM-based are the three shapes it takes.

The defence is escaping by default — every framework's templating does it unless you opt out with dangerously-set-anything — plus a content security policy as the second layer. If user content can ever touch the DOM raw, it eventually will.

Related terms

The bench this belongs to

Cybersecurity

Purple Team: the same person writes the exploit and closes the hole. Most agencies only harden, which means hardening against a threat nobody tested.

All termsStart a conversationMarkdown version

DField Bt. · Dunakeszi · dezso@dfieldsolutions.com
5.0
“From LinkedIn DM to live site. Two tiny tweaks, then shipped.”Michael J Ringer · Vilya ProtectionFounder · Spain