Reflected XSS

Reflected XSS

Description

Writing request parameters directly into an HTML response can cause attacker-controlled scripts to run in the browser.

Potential impact

Attackers may hijack sessions, display phishing content, make requests as the user, or expose user data.

Remediation

Use htmlspecialchars or htmlentities for HTML text and quoted ordinary attribute values. JavaScript, CSS, and URL values require protection appropriate to their output context.

Examples

Before

php
<?php
$html .= '<pre>Hello ' . $_GET['name'] . '</pre>';

After

php
<?php
$name = htmlspecialchars($_GET['name'], ENT_QUOTES, 'UTF-8');
$html .= '<pre>Hello ' . $name . '</pre>';

Explanation:

  • Before: Request input is written into the HTML response without output encoding.
  • After: The value is HTML-encoded before insertion into the text content of the pre element.

References