Skip to content
EduVerse

XSS

Explained

Concept

Also known as: Cross-Site Scripting

An attack that injects malicious JavaScript into a page so it runs in other users’ browsers.

XSS, explained

Written by EduVerse

What it is

Cross-site scripting (XSS) is a security risk where a site shows content from one user to others without handling it safely. If that content contains a script, the browser of every visitor runs it as if it were part of your site.

Why teams use it

A script running inside your page can do whatever the logged-in user can do: read what’s on the screen, make requests in their name or show a fake login form. The standard defences are escaping output by default, sanitising any HTML you must allow, and a Content Security Policy as an extra layer.

An example from work

You’re building a comment section in React and want to support bold text, so you reach for dangerouslySetInnerHTML. The name alone makes a reviewer ask where that HTML comes from. You end up running the comments through a sanitiser library first, or rendering them as plain text.

Our own explanation, not a quote from the book.

In the book

Sentences from The Software Realm, Decoded that mention XSS, exactly as printed.

    1 more passages about XSS in the full book

    Read every conversation where XSS comes up, with the interactive slides and demos.

    See the book

    Where it fits

    Web security, output encoding, Content Security Policy

    Coverage in the book

    Explained

    Explained and compared with alternatives, so you know where and why it’s used.

    Appears in