CompTIA Security+ (SY0-701)Threats, Vulnerabilities, and MitigationsMedium
A user reports that after clicking a link in an email, a pop-up appeared on a trusted banking website displaying their session cookie value. The link contained a script embedded in the URL parameters that the banking site reflected back into the page without sanitization. Which attack does this describe?
- ASQL injection
- BPrivilege escalation
- CMan-in-the-middle attack
- DReflected cross-site scripting
Show answer & explanationAnswer & explanation
Correct answer: D. Reflected cross-site scripting
A script embedded in a URL that the server reflects back into the response, executing in the victim's browser and exposing session data, is the definition of reflected XSS.
Why the other options are wrong
- A. SQL injection targets backend databases, not client-side script execution.
- B. Privilege escalation involves gaining higher access rights, not script injection via URL.
- C. MITM intercepts network traffic between two parties, not injected client-side scripts.
Reflected XSS
A cross-site scripting attack where malicious script is embedded in a request (like a URL) and immediately reflected back by the server into the response, executing in the victim's browser.
- Requires victim to click a crafted malicious link
- Not stored on the server (unlike stored XSS)
- Mitigated by output encoding and input validation
Memory trick: Reflect the script like a mirror bouncing malice back at you.