CompTIA Security+ (SY0-701)Threats, Vulnerabilities, and MitigationsMedium

A user reports that after clicking a link in an email, a pop-up appeared on a trusted banking website displaying their session cookie value. The link contained a script embedded in the URL parameters that the banking site reflected back into the page without sanitization. Which attack does this describe?

  1. ASQL injection
  2. BPrivilege escalation
  3. CMan-in-the-middle attack
  4. DReflected cross-site scripting
Show answer & explanation

Correct answer: D. Reflected cross-site scripting

A script embedded in a URL that the server reflects back into the response, executing in the victim's browser and exposing session data, is the definition of reflected XSS.

Why the other options are wrong

  • A. SQL injection targets backend databases, not client-side script execution.
  • B. Privilege escalation involves gaining higher access rights, not script injection via URL.
  • C. MITM intercepts network traffic between two parties, not injected client-side scripts.

Reflected XSS

A cross-site scripting attack where malicious script is embedded in a request (like a URL) and immediately reflected back by the server into the response, executing in the victim's browser.

  • Requires victim to click a crafted malicious link
  • Not stored on the server (unlike stored XSS)
  • Mitigated by output encoding and input validation

Memory trick: Reflect the script like a mirror bouncing malice back at you.

More Threats, Vulnerabilities, and Mitigations questions