Lazo Lab Sign up

Web Security / Injection

Lesson 9 of 27

Cross-site scripting (XSS)

XSS happens when a site shows user input as HTML, so a visitor's browser runs someone else's script. Escape output and use a Content Security Policy.

Key points

  • Template engines like Jinja escape by default
  • Never mark user input as safe HTML
  • A CSP blocks inline scripts
Watch a video on thisOpens YouTube search results for “Cross-site scripting (XSS)” in a new tab

Quiz · +10 XP

What is the main defence against XSS?

Log in to save progress and earn XP.