CompTIA CySA+ (CS0-003)Vulnerability ManagementMedium
A security analyst is evaluating a web application for potential vulnerabilities. The application takes user input directly from a URL parameter and embeds it into an HTML page without proper sanitization or encoding. Specifically, a parameter `?title=<script>alert('XSS')</script>` causes a pop-up on the user's browser. Which secure coding practice would directly mitigate this type of vulnerability?
- AInput Validation
- BOutput Encoding
- CError Handling
- DParameterized Queries
Show answer & explanationAnswer & explanation
Correct answer: B. Output Encoding
The vulnerability described is a Cross-Site Scripting (XSS) attack. While input validation can help, the most direct and robust mitigation for XSS where user-supplied data is reflected in HTML is 'Output Encoding'. This practice converts potentially malicious characters (like <, >, &) into their safe HTML entities (<, >, &), preventing the browser from interpreting them as executable code.
Why the other options are wrong
- A. Input validation checks if input is valid, but it's not the primary defense against reflected XSS when outputting to HTML; encoding is.
- C. Error handling manages program failures but does not prevent XSS vulnerabilities.
- D. Parameterized queries mitigate SQL injection, not XSS.
Output Encoding
A secure coding practice that translates special characters in user-supplied data into a safe representation before outputting them to a web page or other context, preventing injection attacks like XSS.
- Converts characters like <, >, &, " into HTML entities (e.g., <).
- Essential for preventing Cross-Site Scripting (XSS) attacks.
- Should be applied just before data is rendered in the target context.
Memory trick: Input In, Output Out, Queries Clean, Errors Shout – Secure the code, leave no doubt!