CSS Injection
By Malcolm McDonald Founder, Editor-in-ChiefAuthor of Grokking Web Application Security
Attackers can manipulate user-generated CSS to extract sensitive data.
- Prevalence
- Rare
- Exploitability
- Moderate
- Impact
- Harmful
What is CSS injection?
CSS injection is an injection attack in which an attacker inserts malicious Cascading Style Sheets rules into a page, usually through user-controlled styling or unsanitized input. Using selectors that match attribute values and load external resources, the attacker can exfiltrate sensitive data such as tokens, or alter the interface to mislead users.
What you'll learn
- Why user-supplied styles are an attack vector, even without JavaScript
- How attribute selectors leak a secret token one character at a time
- How a Content Security Policy and CSS sanitization stop the leak
Where this lesson counts
OWASP Top 10
Untrusted input reaches an interpreter as part of a command or query, including SQL, OS and cross-site scripting.
Learn more about A05This lesson includes
-
CSS Injection lab
NerdPress lets bloggers add custom CSS. Watch Mal use attribute selectors to read a visitor's CSRF token one character at a time, each guess showing up as a request in his server logs, until he holds the whole token and can forge requests.
-
How to prevent CSS Injection
The prevention guide covers six approaches:
- Implement a Content Security Policy
- Sanitize and Validate CSS Input
- Escape CSS Context Properly
- Use CSS-in-JS Libraries Safely
- Restrict CSS Property Access
- Deploy a Web Application Firewall
-
CSS Injection quiz
Three questions. Passing marks the lesson complete.
Sources
- CSS injection (reflected) PortSwigger
- CSS Injection Bright Security
- Beyond XSS: Explore the Web Front-end Security Universe Beyond XSS
Related lessons
Browse all 45 lessons
Cross-Site Scripting
If your site allows users to add content, you need to be sure that attackers cannot inject malicious JavaScript.
Reflected XSS
When building a website, you need to be sure you do not accidentally create a channel that allows malicious JavaScript to be bounced off your server.
Information Leakage
Revealing system information helps an attacker learn about your tech stack.
Cross-Site Request Forgery
If an attacker can forge HTTP requests to your site, they may be able to trick your users into triggering unintended actions.