AiVibe

Cybersecurity & Compliance

Cross-Site Scripting (XSS)

A web vulnerability that lets an attacker inject malicious script into pages viewed by other users, so that the script runs in the victim's browser with the privileges of the vulnerable site.

XSS arises when an application includes untrusted data in a web page without encoding it correctly for the context in which it appears. Stored XSS saves the payload on the server, for example in a comment or profile field, and serves it to every visitor. Reflected XSS returns the payload immediately from a request parameter, typically through a crafted link. DOM-based XSS occurs entirely in client-side JavaScript that writes untrusted data into the page.

Because injected script runs within the trusted origin, it can read data on the page, perform actions as the logged-in user, capture keystrokes or redirect to phishing pages, and it can steal session cookies that lack the HttpOnly attribute. XSS is among the most frequently reported web vulnerabilities, is catalogued as CWE-79 and was merged into the injection category in the OWASP Top 10 2021.

Prevention relies on context-aware output encoding, frameworks that escape output by default, sanitisation of any user-supplied HTML with a well-maintained library and avoidance of APIs that insert raw HTML. A strict Content Security Policy limits the impact of any remaining flaw, and the HttpOnly attribute keeps session cookies out of reach of scripts. Testing combines code review, static analysis and dynamic scanning.

Key points

Where AiVibe comes in

AiVedha.ai's automated website security audit covers XSS among more than 170 checks, with severity ratings and remediation steps in its report.

Explore AiVibe’s work in Cybersecurity & Compliance →

Related terms

Terms that refer to Cross-Site Scripting (XSS)

Ask AiMuruga can explain Cross-Site Scripting (XSS) for your plant, product or security programme, and draw how it fits.