CompTIA PenTest+ (PT0-003)Attacks and ExploitsMedium
During a web application test, a tester posts a malicious script into a public product review field. The application saves the review in its database, and every subsequent visitor who views that product page has the script execute in their browser. Which type of XSS is this?
- ASQL injection
- BServer-side request forgery
- CStored cross-site scripting
- DReflected cross-site scripting
Show answer & explanationAnswer & explanation
Correct answer: C. Stored cross-site scripting
Because the payload is written to the database and served to every user who views the product page, this is stored (persistent) XSS, which is generally considered more dangerous than reflected XSS due to its wider blast radius.
Why the other options are wrong
- A. SQL injection targets the database query layer, not browser script execution.
- B. SSRF involves the server making unauthorized requests, unrelated to client-side script execution.
- D. Reflected XSS requires the payload to be part of each request, not stored.
Stored XSS
A persistent cross-site scripting attack where malicious script is saved on the server (e.g., in a database) and executes for every user who views the affected content.
- Also called persistent XSS
- More dangerous than reflected XSS due to broad, automatic exposure
- Common in comment fields, forums, and user profiles
Memory trick: Stored = script sleeps in the database, wakes for every visitor