Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Attack Patterns CAPEC-591 — Reflected XSS
CAPEC-591

Reflected XSS

TLP:CLEAR

Description

Typical severity: Very High. Likelihood of attack: High. This type of attack is a form of Cross-Site Scripting (XSS) where a malicious script is "reflected" off a vulnerable web application and then executed by a victim's browser. The process starts with an adversary delivering a malicious script to a victim and convincing the victim to send the script to the vulnerable web application.

Mitigation

Use browser technologies that do not allow client-side scripting. | Utilize strict type, character, and encoding enforcement. | Ensure that all user-supplied input is validated before use.

Details

Platforms
Software
Added
Jul 14, 2026
Leaving Threaticon

This link opens an external site that isn't part of the platform.