flawopen.com/Cross-Site Scripting/Javascript

Cross-Site Scripting in Javascript

Hoch CWE-79 Draft — pending review
Language: English Português (Brasil) Español Français Deutsch Русский 简体中文 日本語 हिन्दी 한국어 Bahasa Indonesia
Einfach erklärt

Imagine a guestbook where a visitor writes a note containing hidden script tags that execute in the browser of the next person who opens the page.

Schlüsselbegriffe auf dieser Seite
output encoding
Converting special markup characters into safe entities so browsers display them as text rather than script.

Was passiert

Cross-site scripting happens when untrusted user input is inserted into the DOM without proper HTML output encoding.

Auswirkung in der Praxis

In 2005, the Samy XSS worm infected over 1 million user profiles on MySpace in under 20 hours, forcing the platform offline.

Documented historical AppSec case study.

Verwundbar vs. behoben

VULNERABLE
// comment text parsed directly as HTML
function renderComment(el, comment) {
  el.innerHTML =
    `

${comment}

`; }
FIXED
// comment text inserted as safe plain text
function renderComment(el, comment) {
  const p = document.createElement('p');
  p.textContent = comment;
  el.appendChild(p);
}

Warum die Behebung funktioniert

textContent inserts values strictly as plain text, preventing the browser from parsing markup into executable elements.

Sprachspezifische Gotchas

React dangerouslySetInnerHTML

Explicitly disables React auto-escaping. Must be paired with DOMPurify if used.

Häufige Missverständnisse

"Frameworks prevent all XSS"

Template escape hatches and direct DOM APIs (innerHTML, outerHTML) bypass framework defenses.

Wie Sie prüfen, ob Sie betroffen sind

grep -rn "\.innerHTML\s*=" --include="*.js" --include="*.ts" . grep -rn "dangerouslySetInnerHTML" --include="*.jsx" --include="*.tsx" .
Configure ESLint rule react/no-danger and DOMPurify for cases where HTML formatting is genuinely required.

Präventions-Checkliste

Häufig gestellte Fragen

Does Content Security Policy (CSP) replace escaping?

No. CSP provides defense-in-depth, but output encoding remains the primary defense.

Referenzen

Siehe auch: SQL Injection Command InjectionPath Traversal