SecurityFrontend

XSS

Also written as Cross-Site Scripting

A vulnerability where an attacker injects malicious script into a web page that then runs in other users' browsers, often to steal their session or data.

Think of it like

Like someone sneaking a fake, malicious insert into a newsletter that gets printed and mailed to every subscriber.

Junior or senior?

Junior sounds like

Knows XSS is bad but can't explain the mechanism.

Senior sounds like

Can explain how their team sanitized or escaped user-submitted content to prevent it.

Ask them

“How did your team sanitize or escape user-submitted content to prevent XSS?”