1. Support Center
  2. Cross-Site Scripting (XSS)

Cross-Site Scripting (XSS)

Cross-site scripting is the injection of client-side scripts into web applications, which is enabled by a lack of validating and correctly encoding user input. Learn here, how you can efficiently fix XSS vulnerabilities.

AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NSecurity Assessment

Security_Assessment_XSS-1

CVSS Vector: AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Vulnerability Information

Cross-site scripting (XSS) is the injection of client-side scripts into web applications, which is enabled by a lack of validating and correctly encoding user input. The malicious scripts are executed within the end user’s browser and enable various attacks, from stealing the end-users session to monitoring and altering all actions performed by the end-user on the affected website. This is possible whenever user input (for example, on a website) is not sufficiently validated on the client- or the server-side.

This includes altering all user actions on that website since the browser does not know that this script cannot be trusted. Because this script is trusted, it can access, e.g., cookies or session tokens or even alter the content of an HTML Page.

It can be injected persistently or non-persistently, depending on the type of XSS that is being used. Usual vehicles of cross-site scripting attacks include search forms, forums, or comment sections.

Cross-Site Scripting attacks are very common in web applications and APIs.

Types

There are different types of cross-site scripting attacks, which are introduced in the following sections.

Stored Cross-Site Scripting (Persistent)

There are different types of XSS attacks, which distinguish if the malicious scripts could be injected in a non-persistent or persistent fashion. Furthermore, there is a differentiation between the vulnerability caused by a flawed input validation on the client- or server-side.

There 3 main types of cross-site scripting attacks are:

  1. Stored XSS
  2. Reflected XSS
  3. Dom-based XSS

Stored Cross-Site Scripting (Persistent)

Stored Cross-site Scripting vulnerability allows an attacker to inject a malicious script persistently into a web application.

In a Stored XSS example, the script might have been submitted via an input field to the web server, which did not perform a sufficient validation and stores the script persistently in the database. The consequence of this might be that this script is now being delivered to all users visiting the web application and, e.g., able to gain access to the user’s session cookies.

  • Script is persistently stored in web app
  • Users visiting the app after the infection retrieve the script
  • Malicious code exploits flaws in the web application
  • The script and the attack is visible on the server-side (to the app owner)

Reflected Cross-Site Scripting (Non-Persistent)

Reflected Cross-site Scripting Vulnerability appears if unvalidated input is directly displayed to the user.

In a Reflected XSS example, the input of a search form is reflected on the page to show what the search key was. An attacker may craft an URL that contains malicious code and spread the URL via e-mail or social media. A user who clicks on this link opens the (valid) web application, which then runs the malicious code in the user’s browser.

  • Script is not stored in the web application 
  • Malicious code is shown to only one user
  • Users that open the link execute the script when an app is opened
  • The script and the attack is not necessarily visible on the server-side (to the app owner)

DOM-Based Cross-Site Scripting

DOM stands for Document Object Model and is an interface to web pages. It is essentially an API to the page, allowing programs to read and manipulate the page’s content, structure, and styles.

DOM-based XSS attack may be successfully executed even when the server does not embed any malicious code into the webpage by using a flaw in the JavaScript executed in the web browser. For example, if the client site JavaScript modifies the DOM tree of the webpage based on an input field or GET parameter without validating the input, malicious code can be executed.

  • Script is not stored in the web application
  • Malicious code is shown to only one user
  • Malicious code exploits flaws in the browser on the user side
  • The script and the attack is not necessarily visible on the server-side (to the app owner)

Guides

To prevent XSS attacks treat all user input as potentially malicious and follow some programming guidelines:

Avoid Untrusted Input

XSS attacks only appear if any user input is displayed on the webpage. Therefore try to avoid displaying any (untrusted) user input, if possible. If you need to display user data, restrict the places where the user input might appear. Any input displayed inside a JavaScript tag or a URL shown on the site is much more likely to be exploited than the input that appears inside a div or span element inside the HTML body.

Filter User Input

When any untrusted input is shown as normal text inside an HTML tag, filter out the characters that allow an attacker to insert a <script> tag in the page. Use the following functions for that:

htmlspecialchars($input)                                    # PHP
html.escape(input, quote=True) # Python
org.apache.commons.lang.StringEscapeUtils.escapeHtml(input) # Java

In JavaScript, you need to define an extra function for this task. You may use:

function escapeHtml(text) {
var map = {
'&': '&amp;',
'<': '&lt;',
'>': '&gt;',
'"': '&quot;',
"'": '&#039;'
};

return text.replace(/[&<>"']/g, function(m) { return map[m]; });
}

When user input needs to be inserted into tag attributes or inside a script, you will need to use stronger escape mechanisms. Refer to the XSS Prevention Cheat Sheet for more information. This is the case if you plan to allow user input in cases such as:

<a href="http://example.org/search/q?...USER INPUT..."></div>
<script>alert('...USER INPUT...')</script>
<style> { property: ...USER INPUT...; } </style>

Fix DOM-based XSS

To prevent a DOM-based XSS attack you could use a save JavaScript property like ‘element.text content for untrusted user input. This prevents the browser from rendering the potential JavaScript code inside the ‘untrustedVariable.’ One of the Dom XSS examples could look like the following code snippet:

element.textContent = untrustedVariable

Furthermore, it is important to use secure JavaScript functions like ‘inner text or ‘text content instead of ‘innerHtml.’ It is always good to keep in mind that it is perilous to pass user-controlled inputs into your web application without proper sanitization.

For further information, OWASP provides a specific DOM-based XSS Prevention Cheat Sheet, including an additional set of rules for securing your web application from DOM-based XSS.

Use a XSS Vulnerability Tool

Like mentioned earlier, XSS attacks are sometimes difficult to detect. However, this can be changed if you get some external help. Another way to prevent XSS Attacks is using the XSS Tool from Crashtest Security Suite – a web vulnerability scanner with a 14-day free trial where you will find any vulnerability you could be exposed to. Still, manual testing is highly time-consuming and costly – and therefore not possible to be done for every iteration of your web application.

Consequently, your code shouldn’t be untested before any release.

Using automated security, you can scan your web application for Cross-Site Scripting and other critical vulnerabilities before every release you do. This way, you can ensure that your web application’s Live-Version is still secured whenever you alter or add a feature.

Enable Content Security Policy (CSP)

This can prevent not just Cross-Site Scripting attacks but also Cross-Site Injection attacks.

For more information about Crashtest Security visit crashtest-security.com or go to our XSS Page!