SecurityFrontend
XSS
Also written as Cross-Site Scripting
A vulnerability where an attacker injects malicious script into a web page that then runs in other users' browsers, often to steal their session or data.
Think of it like
Like someone sneaking a fake, malicious insert into a newsletter that gets printed and mailed to every subscriber.
Junior or senior?
Junior sounds like
Knows XSS is bad but can't explain the mechanism.
Senior sounds like
Can explain how their team sanitized or escaped user-submitted content to prevent it.
Ask them
“How did your team sanitize or escape user-submitted content to prevent XSS?”