CompTIA CySA+ (CS0-003)Vulnerability ManagementMedium

A security analyst is evaluating a web application for potential vulnerabilities. The application takes user input directly from a URL parameter and embeds it into an HTML page without proper sanitization or encoding. Specifically, a parameter `?title=<script>alert('XSS')</script>` causes a pop-up on the user's browser. Which secure coding practice would directly mitigate this type of vulnerability?

  1. AInput Validation
  2. BOutput Encoding
  3. CError Handling
  4. DParameterized Queries
Show answer & explanation

Correct answer: B. Output Encoding

The vulnerability described is a Cross-Site Scripting (XSS) attack. While input validation can help, the most direct and robust mitigation for XSS where user-supplied data is reflected in HTML is 'Output Encoding'. This practice converts potentially malicious characters (like <, >, &) into their safe HTML entities (&lt;, &gt;, &amp;), preventing the browser from interpreting them as executable code.

Why the other options are wrong

  • A. Input validation checks if input is valid, but it's not the primary defense against reflected XSS when outputting to HTML; encoding is.
  • C. Error handling manages program failures but does not prevent XSS vulnerabilities.
  • D. Parameterized queries mitigate SQL injection, not XSS.

Output Encoding

A secure coding practice that translates special characters in user-supplied data into a safe representation before outputting them to a web page or other context, preventing injection attacks like XSS.

  • Converts characters like <, >, &, " into HTML entities (e.g., &lt;).
  • Essential for preventing Cross-Site Scripting (XSS) attacks.
  • Should be applied just before data is rendered in the target context.

Memory trick: Input In, Output Out, Queries Clean, Errors Shout – Secure the code, leave no doubt!

More Vulnerability Management questions