XSS
ExplainedConcept
Also known as: Cross-Site Scripting
An attack that injects malicious JavaScript into a page so it runs in other users’ browsers.
XSS, explained
Written by EduVerseWhat it is
Cross-site scripting (XSS) is a security risk where a site shows content from one user to others without handling it safely. If that content contains a script, the browser of every visitor runs it as if it were part of your site.
Why teams use it
A script running inside your page can do whatever the logged-in user can do: read what’s on the screen, make requests in their name or show a fake login form. The standard defences are escaping output by default, sanitising any HTML you must allow, and a Content Security Policy as an extra layer.
An example from work
You’re building a comment section in React and want to support bold text, so you reach for dangerouslySetInnerHTML. The name alone makes a reviewer ask where that HTML comes from. You end up running the comments through a sanitiser library first, or rendering them as plain text.
Our own explanation, not a quote from the book.
In the book
Sentences from The Software Realm, Decoded that mention XSS, exactly as printed.
1 more passages about XSS in the full book
Read every conversation where XSS comes up, with the interactive slides and demos.
Where it fits
Web security, output encoding, Content Security Policy
Coverage in the book
Explained and compared with alternatives, so you know where and why it’s used.