XSS (Cross-Site Scripting) is a vulnerability class where an attacker injects malicious JavaScript into a web page viewed by other users.
Types
- Stored XSS — payload is persisted on the server (DB, comments).
- Reflected XSS — payload is echoed back in the server response.
- DOM-based XSS — client-side DOM manipulation without server involvement.
Impact
Session/cookie theft, form hijacking, phishing, drive-by download.
Mitigation
Output encoding, Content-Security-Policy headers, HTTPOnly cookies.