Web Apps Intermediate

Cross-Site Scripting (XSS)

Reflected, stored, and DOM-based XSS: how each is delivered, how to break out of every context, and why CSP plus output encoding is the real fix.

Beaulah Marks 5 lessons

About this class

What you'll learn

XSS lets an attacker run JavaScript in another user's browser on the target origin — with that user's session and access. This class covers the three types, the context problem (HTML vs. attribute vs. JavaScript vs. URL), filter bypass, and prevention.

Practice

Pair with the reflected XSS in a search field and stored XSS to session theft labs.

On this page

Price

0.0120 BTC

≈ $780.00

Sign In to Enrol

At a glance

Category
Web Apps
Difficulty
Intermediate
Lessons
5 · 2 free
Total time
1h 22m
Students
0 enrolled
Tutor
Beaulah Marks
Published
Sep 2026