Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Attack Patterns CAPEC-63 — Cross-Site Scripting (XSS)
CAPEC-63

Cross-Site Scripting (XSS)

TLP:CLEAR

Description

Typical severity: Very High. Likelihood of attack: High. An adversary embeds malicious scripts in content that will be served to web browsers. The goal of the attack is for the target software, the client-side browser, to execute the script with the users' privilege level. An attack of this type exploits a programs' vulnerabilities that are brought on by allowing remote hosts to execute code and scripts. Web browsers, for example, have some simple security controls in place, but if a remote attacker is allowed to execute scripts (through injecting them in to user-generated content like bulletin boards) then these controls may be bypassed. Further, these attacks are very difficult for an end user to detect.

Mitigation

Design: Use browser technologies that do not allow client side scripting. | Design: Utilize strict type, character, and encoding enforcement | Design: Server side developers should not proxy content via XHR or other means, if a http proxy for remote content is setup on the server side, the client's browser has no way of discerning where the data is originating from. | Implementation: Ensure all content that is delivered to client is sanitized against an acceptable content specification. | Implementation: Perform input validation for all remote content.

Details

Platforms
Software
Added
Jul 14, 2026
Leaving Threaticon

This link opens an external site that isn't part of the platform.