Understanding Cross-site scripting
What it is
Cross-site scripting is what happens when input becomes executable script in somebody else's browser. If a value you supply is reflected into a page — or stored and shown to others — without being encoded for its context, you can make the page run code as any visitor who sees it.
How you approach it
- Find every place your input comes back out onto the page. One of them is not being encoded — where does your text land verbatim?
- Work out the context it lands in: inside a tag, an attribute, a script block? The payload that breaks out differs for each.
- Once your script runs, the flag is somewhere the page can read but the screen does not show — a cookie, a variable, a hidden field.
How it gets fixed
A value was written into the page without being encoded for the context it landed in, so a crafted payload broke out of that context and executed. From there the injected script could read what the page held. The fix is contextual output encoding, plus a Content-Security-Policy that refuses inline script.
Practise it
Every lab in the Cross-site scripting (XSS) category drills exactly this. Start at Apprentice and work up.