Learning path

Full curriculum

Full curriculum

Unit content

Cross-site scripting and contextual output encoding

Cross-site scripting (XSS) occurs when attacker-controlled data is inserted into a web page so the browser interprets it as active content rather than inert data.

If untrusted text is placed directly into HTML source, characters such as <, >, quotes or script-bearing markup can change the document structure.

The primary defense is contextual output encoding: data inserted into HTML text, an HTML attribute, JavaScript source or a URL must be encoded for that specific syntactic context.

Modern templating systems often escape ordinary text substitutions automatically. Bypassing that escaping or inserting prebuilt “safe HTML” moves responsibility back to the application.

XSS is especially serious because injected script executes with the origin privileges of the vulnerable site. It can read data available to that origin, issue authenticated requests and manipulate the interface shown to the user.

Input validation can restrict allowed values, but it does not replace correct output encoding at the point where data enters executable browser syntax.