What is cross-site scripting?¶
Cross-site scripting allows attacker-controlled content to execute in another user's browser within a trusted application's context. Finding or storing a payload does not prove another user received or ran it.
Identify the delivery route¶
Reflected XSS usually requires a crafted request or link; stored XSS remains in an application and may affect later viewers; client-side logic may create another route. Preserve the submitted input, stored object, publication history and affected requests.
Determine whether sanitisation or browser controls blocked execution and which users or sessions received the content.
Prove browser execution and effect¶
Browser, security and session records may show script execution, redirection, input capture, session use or actions performed as the user. Application submission logs alone prove only the input stage.
Limit scope to affected sessions. A vulnerable page does not mean every visitor was compromised, and payload presence does not identify its author without account and infrastructure evidence.
Key takeaway
Prove XSS through submission, delivery to a specific browser, execution and resulting session effect, distinguishing reflected, stored and client-side routes.