How Attackers Use It
Attack Summary
Malicious JavaScript is injected into a page and executed in other users' browsers. Used for session token theft, keylogging, defacement, and drive-by download distribution.
- Attacker identifies an input or rendering sink that reflects unsanitized content.
- Payload execution is validated in target browsers and rendering contexts.
- Session theft, credential capture, and malicious redirects are chained.
- Persistent vectors can hit all users viewing compromised content.