Web Security & OWASP Top 10 · question
Question 8 of 45
What is XSS and what are the three main types?
← All Web Security & OWASP Top 10 questions
Re-explain
Cross-Site Scripting (XSS) allows attackers to inject malicious scripts into web pages viewed by other users.
Three main types:
Stored XSS (Persistent): Malicious script stored on server
- Example: Comment section storing
<script>alert('XSS')</script>
Reflected XSS (Non-persistent): Script reflected from request
- Example: Search parameter displayed without encoding
DOM-based XSS: Vulnerability in client-side JavaScript
- Example:
document.write(location.hash.substring(1))
Impact: Session hijacking, credential theft, defacement, malware distribution
Prevention: Input validation, output encoding, Content Security Policy (CSP), sanitization
Rewriting in plainer words…
This answer doesn't lend itself to a diagram - it reads best . No credits were charged.
Why there's no diagram: “”
The diagram below the answer is the concept .
Jump to it ↓
What should the new diagram focus on?
How well did you know this?
AI:
Saved in this browser - sign in to keep your review list.
How should your speech become text?
Listening… your words appear above as you speak - tap Stop when you're done.
Recording · cr - tap Stop & transcribe when you're done.
Transcribing with AI…
Voice:
Keep going - a few more words and AI can grade it.
Interview lens
Likely follow-ups, what you can say, and the weak answers to avoid.
Pro · $10/mo
39 of 45 Web Security & OWASP Top 10 answers are in Pro.
Full answers, code samples, and AI explanations that go simpler or deeper. Cancel anytime.
-
Full answers + code
-
AI explanations, simpler or deeper
-
1,000 AI credits / month
-
Cancel anytime