15–25 min Updated

CSS Injection

By Malcolm McDonald Founder, Editor-in-ChiefAuthor of Grokking Web Application Security

Attackers can manipulate user-generated CSS to extract sensitive data.

Prevalence
Rare
Exploitability
Moderate
Impact
Harmful

What is CSS injection?

CSS injection is an injection attack in which an attacker inserts malicious Cascading Style Sheets rules into a page, usually through user-controlled styling or unsanitized input. Using selectors that match attribute values and load external resources, the attacker can exfiltrate sensitive data such as tokens, or alter the interface to mislead users.

What you'll learn

  • Why user-supplied styles are an attack vector, even without JavaScript
  • How attribute selectors leak a secret token one character at a time
  • How a Content Security Policy and CSS sanitization stop the leak

Where this lesson counts

OWASP Top 10

  • CSS Injection lab

    NerdPress lets bloggers add custom CSS. Watch Mal use attribute selectors to read a visitor's CSRF token one character at a time, each guess showing up as a request in his server logs, until he holds the whole token and can forge requests.

  • How to prevent CSS Injection

    The prevention guide covers six approaches:

    • Implement a Content Security Policy
    • Sanitize and Validate CSS Input
    • Escape CSS Context Properly
    • Use CSS-in-JS Libraries Safely
    • Restrict CSS Property Access
    • Deploy a Web Application Firewall
  • CSS Injection quiz

    Three questions. Passing marks the lesson complete.

Sources

  • Cross-Site Scripting

    If your site allows users to add content, you need to be sure that attackers cannot inject malicious JavaScript.

  • Reflected XSS

    When building a website, you need to be sure you do not accidentally create a channel that allows malicious JavaScript to be bounced off your server.

  • Information Leakage

    Revealing system information helps an attacker learn about your tech stack.

  • Cross-Site Request Forgery

    If an attacker can forge HTTP requests to your site, they may be able to trick your users into triggering unintended actions.