# Cross-site scripting (XSS)

> An attack that injects hostile JavaScript into a page other people view — the browser runs the attacker's code with the victim's session.

The page is trusted; anything that lands on it inherits that trust. If a comment, a profile field or a URL parameter reaches the HTML unescaped, the attacker's script runs in every visitor's browser — reading session tokens, keylogging, acting as the user. Stored, reflected and DOM-based are the three shapes it takes.

The defence is escaping by default — every framework's templating does it unless you opt out with dangerously-set-anything — plus a content security policy as the second layer. If user content can ever touch the DOM raw, it eventually will.

## Related terms

- https://dfieldsolutions.com/en/glossary/csrf.md
- https://dfieldsolutions.com/en/glossary/csp.md
- https://dfieldsolutions.com/en/glossary/owasp-top-10.md

---

Source: https://dfieldsolutions.com/en/glossary/xss
DField Solutions — Dunakeszi, Hungary — dezso@dfieldsolutions.com
Booking: see https://dfieldsolutions.com/en/contact
