PractitionerCross-site scripting (XSS)
Client-Side Attacks
The browser is a hostile place to keep a secret. This path covers reflected and stored XSS, breaking out of contexts, and the CSRF that fires an action as a victim who only visited a page.
The browser is a hostile place to keep a secret. This path covers reflected and stored XSS, breaking out of contexts, and the CSRF that fires an action as a victim who only visited a page.