Web Security / Injection
Lesson 9 of 27
Cross-site scripting (XSS)
XSS happens when a site shows user input as HTML, so a visitor's browser runs someone else's script. Escape output and use a Content Security Policy.
Key points
- Template engines like Jinja escape by default
- Never mark user input as safe HTML
- A CSP blocks inline scripts
Quiz · +10 XP
What is the main defence against XSS?
Log in to save progress and earn XP.