Client-Side Attacks
Cross-Site Scripting (XSS) allows attackers to inject malicious scripts into web pages viewed by other users.
Types of XSS
XSS Impact
Defenses
& " ' to HTML entities before rendering
โ <script> instead of
Injecting malicious scripts into web pages
โถ Continue where you left offCross-Site Scripting (XSS) allows attackers to inject malicious scripts into web pages viewed by other users.
& " ' to HTML entities before rendering
โ <script> instead of