ISC2 CISSP (Certified Information Systems Security Professional)Security Architecture and EngineeringMedium
A security auditor is reviewing a web application and discovers that it is vulnerable to Cross-Site Scripting (XSS). Which OWASP Top 10 category does XSS primarily fall under, and what is the fundamental cause of this vulnerability?
- AInjection; improper input validation and output encoding.
- BSecurity Misconfiguration; default credentials or unpatched systems.
- CSensitive Data Exposure; lack of encryption for personal information.
- DBroken Authentication; inadequate session management.
Show answer & explanationAnswer & explanation
Correct answer: A. Injection; improper input validation and output encoding.
Cross-Site Scripting (XSS) is a type of Injection vulnerability. It occurs when an application includes untrusted data in an HTML page without proper validation or escaping, allowing attackers to inject client-side scripts into web pages viewed by other users.
Why the other options are wrong
- B. Security Misconfiguration involves incorrect server or application settings, not specifically script injection.
- C. Sensitive Data Exposure deals with protecting data confidentiality, not the execution of arbitrary scripts in a user's browser.
- D. Broken Authentication relates to flaws in identity verification, not script injection.
Cross-Site Scripting (XSS)
A web security vulnerability that enables attackers to inject client-side scripts into web pages viewed by other users.
- Occurs when an application embeds untrusted input into its output without proper sanitization.
- Can lead to session hijacking, defacement, or redirection.
- Mitigated by input validation and output encoding.
Memory trick: Injection is Input's Enemy.