datacoconut
Programs
AboutSign in
LabsCoursesConceptsVideosAcademy
← All courses
PractitionerCross-site scripting (XSS)

Client-Side Attacks

The browser is a hostile place to keep a secret. This path covers reflected and stored XSS, breaking out of contexts, and the CSRF that fires an action as a victim who only visited a page.

Syllabus

  1. 1Understanding cross-site scriptingReading10 min
  2. 2Lab: reflected in the search boxLab20 min
  3. 3Lab: stored in a display nameLab45 min
  4. 4Understanding CSRFReading10 min
  5. 5Lab: the form with no tokenLab45 min
datacoconut
© 2026 datacoconut · All rights reserved