Cisco Certified Support Technician (CCST) CybersecuritySecurity PrinciplesMedium

A cybersecurity team is evaluating a software application for potential vulnerabilities. They discover that the application does not properly sanitize user input, allowing malicious scripts to be injected and executed in a user's web browser when viewing affected content. Which type of vulnerability does this scenario describe?

  1. ACross-Site Scripting (XSS)
  2. BBuffer Overflow
  3. CDenial of Service (DoS)
  4. DSQL Injection
Show answer & explanation

Correct answer: A. Cross-Site Scripting (XSS)

The scenario describes an attacker injecting malicious client-side scripts into web pages viewed by other users due to improper input sanitization. This is the definition of a Cross-Site Scripting (XSS) vulnerability.

Why the other options are wrong

  • B. Buffer Overflow occurs when a program writes data beyond the allocated buffer memory, leading to crashes or code execution.
  • C. Denial of Service (DoS) aims to make a service unavailable, not to execute scripts in a user's browser.
  • D. SQL Injection targets databases by injecting malicious SQL queries, not client-side scripts.

Cross-Site Scripting (XSS)

A type of security vulnerability typically found in web applications. XSS enables attackers to inject client-side scripts into web pages viewed by other users. An XSS vulnerability may be used by attackers to bypass access controls, impersonate users, or steal session cookies.

  • Involves injecting malicious JavaScript or HTML.
  • Executes in the victim's browser, not the server.
  • Often results from improper input validation/sanitization.

Memory trick: Web attacks: SQL is database, XSS is browser, DDoS is traffic.

More Security Principles questions