High severity Vulnerability

Cross-Site Scripting (XSS)

Attacker-supplied script runs in another user's browser, stealing sessions and rewriting the page.

Overview

XSS occurs when a page reflects, stores or DOM-injects data without contextual encoding.\nThree variants exist: reflected (payload rides in the URL), stored (payload persists in the database) and DOM-based (the sink is pure client-side JavaScript).\nImpact ranges from session theft and credential harvesting to cryptomining and worm-like propagation.

Indicators of Compromise

Signals that suggest this is present on a system.

  • Script tags accepted in comment or profile fields
  • Alert dialogs firing from URL parameters
  • Unexpected third-party script origins

Controls that stop it

  • Encode Output Contextually

    Escape data at the moment it is rendered, using the encoding that matches its context: HTML body, HTML attribute, JavaScript, URL or CSS. Combine this with a Content-Security-Policy that forbids inline script, so a missed escape degrades to a broken element instead of code execution.

We use only the cookies needed to run this site — your session, your sign-in state and CSRF protection. There are no advertising or analytics trackers. How cookies are used