Web Apps
Intermediate
Cross-Site Scripting (XSS)
Reflected, stored, and DOM-based XSS: how each is delivered, how to break out of every context, and why CSP plus output encoding is the real fix.
Beaulah Marks
5 lessons
About this class
What you'll learn
XSS lets an attacker run JavaScript in another user's browser on the target origin — with that user's session and access. This class covers the three types, the context problem (HTML vs. attribute vs. JavaScript vs. URL), filter bypass, and prevention.
Practice
Pair with the reflected XSS in a search field and stored XSS to session theft labs.
Curriculum
On this page
Price
0.0120 BTC≈ $780.00
At a glance
- Category
- Web Apps
- Difficulty
- Intermediate
- Lessons
- 5 · 2 free
- Total time
- 1h 22m
- Students
- 0 enrolled
- Tutor
- Beaulah Marks
- Published
- Sep 2026