QamoosTech
SecurityIntermediate

Cross-Site Scripting (XSS)

PronunciationKROSS-syt SKRIP-ting

Definition

A security vulnerability that allows attackers to inject malicious client-side scripts into web pages viewed by other users. This usually happens when an application takes user input and renders it in the browser without proper validation or escaping.

Where you hear it

In security audits, penetration testing reports, code reviews, and when discussing input sanitization.

Examples

  • The security scan flagged an XSS vulnerability in the user profile comment section.
  • We must sanitize all user inputs to prevent stored XSS attacks.

Common mistake

Thinking XSS only affects other users; attackers can also use stored XSS to target administrators and compromise the entire application.