Cisco Certified Support Technician (CCST) CybersecuritySecurity PrinciplesMedium
A cybersecurity team is evaluating a software application for potential vulnerabilities. They discover that the application does not properly sanitize user input, allowing malicious scripts to be injected and executed in a user's web browser when viewing affected content. Which type of vulnerability does this scenario describe?
- ACross-Site Scripting (XSS)
- BBuffer Overflow
- CDenial of Service (DoS)
- DSQL Injection
Show answer & explanationAnswer & explanation
Correct answer: A. Cross-Site Scripting (XSS)
The scenario describes an attacker injecting malicious client-side scripts into web pages viewed by other users due to improper input sanitization. This is the definition of a Cross-Site Scripting (XSS) vulnerability.
Why the other options are wrong
- B. Buffer Overflow occurs when a program writes data beyond the allocated buffer memory, leading to crashes or code execution.
- C. Denial of Service (DoS) aims to make a service unavailable, not to execute scripts in a user's browser.
- D. SQL Injection targets databases by injecting malicious SQL queries, not client-side scripts.
Cross-Site Scripting (XSS)
A type of security vulnerability typically found in web applications. XSS enables attackers to inject client-side scripts into web pages viewed by other users. An XSS vulnerability may be used by attackers to bypass access controls, impersonate users, or steal session cookies.
- Involves injecting malicious JavaScript or HTML.
- Executes in the victim's browser, not the server.
- Often results from improper input validation/sanitization.
Memory trick: Web attacks: SQL is database, XSS is browser, DDoS is traffic.