ISC2 CISSP (Certified Information Systems Security Professional)Security Architecture and EngineeringMedium

A security auditor is reviewing a web application and discovers that it is vulnerable to Cross-Site Scripting (XSS). Which OWASP Top 10 category does XSS primarily fall under, and what is the fundamental cause of this vulnerability?

  1. AInjection; improper input validation and output encoding.
  2. BSecurity Misconfiguration; default credentials or unpatched systems.
  3. CSensitive Data Exposure; lack of encryption for personal information.
  4. DBroken Authentication; inadequate session management.
Show answer & explanation

Correct answer: A. Injection; improper input validation and output encoding.

Cross-Site Scripting (XSS) is a type of Injection vulnerability. It occurs when an application includes untrusted data in an HTML page without proper validation or escaping, allowing attackers to inject client-side scripts into web pages viewed by other users.

Why the other options are wrong

  • B. Security Misconfiguration involves incorrect server or application settings, not specifically script injection.
  • C. Sensitive Data Exposure deals with protecting data confidentiality, not the execution of arbitrary scripts in a user's browser.
  • D. Broken Authentication relates to flaws in identity verification, not script injection.

Cross-Site Scripting (XSS)

A web security vulnerability that enables attackers to inject client-side scripts into web pages viewed by other users.

  • Occurs when an application embeds untrusted input into its output without proper sanitization.
  • Can lead to session hijacking, defacement, or redirection.
  • Mitigated by input validation and output encoding.

Memory trick: Injection is Input's Enemy.

More Security Architecture and Engineering questions