Overview
XSS occurs when a page reflects, stores or DOM-injects data without contextual encoding.\nThree variants exist: reflected (payload rides in the URL), stored (payload persists in the database) and DOM-based (the sink is pure client-side JavaScript).\nImpact ranges from session theft and credential harvesting to cryptomining and worm-like propagation.
Indicators of Compromise
Signals that suggest this is present on a system.
- Script tags accepted in comment or profile fields
- Alert dialogs firing from URL parameters
- Unexpected third-party script origins
Controls that stop it
-
Encode Output Contextually
Escape data at the moment it is rendered, using the encoding that matches its context: HTML body, HTML attribute, JavaScript, URL or CSS. Combine this with a Content-Security-Policy that forbids inline script, so a missed escape degrades to a broken element instead of code execution.