DOM-based XSS
By Malcolm McDonald Founder, Editor-in-ChiefAuthor of Grokking Web Application Security
If you make use of URI fragments in your site, you need to ensure they cannot be abused to inject malicious JavaScript.
- Prevalence
- Rare
- Exploitability
- Easy
- Impact
- Harmful
What is DOM-based XSS?
DOM-based XSS is a cross-site scripting (XSS) attack, a type of injection attack, that takes place entirely in the browser. Client-side JavaScript reads attacker-controlled data, often from the URI fragment, and writes it into the page without escaping, so the attacker's script runs. Because the payload may never be sent to the server, server-side defenses cannot detect it.
What you'll learn
- What a URI fragment is and why the server never sees it
- How client-side code that writes unescaped data into the page runs attacker scripts
- How frameworks, code audits and a Content Security Policy prevent DOM-based XSS
Where this lesson counts
OWASP Top 10
Untrusted input reaches an interpreter as part of a command or query, including SQL, OS and cross-site scripting.
OWASP 2025 folds cross-site scripting into Injection: untrusted input reaching the HTML interpreter.
Learn more about A05PCI DSS 4.0
Requirement 6.2.4: engineering techniques must prevent injection, data-structure, cryptographic, business-logic and access-control attacks in bespoke software.
Learn more about 6.2.4Requirement 6.4.1: public-facing web applications must be protected against known attacks by regular vulnerability review or an automated technical solution.
Learn more about 6.4.1This lesson includes
-
DOM-based XSS lab
A site with infinite scroll tracks your position in the URL fragment and writes it into the page without checking it. See how an attacker puts JavaScript in the fragment, and how it runs in the browser of anyone who follows the link.
-
How to prevent DOM-based XSS
The prevention guide covers six approaches:
- Use a JavaScript Framework
- Audit Your Code Carefully
- Parse JSON Carefully
- Detect Unsafe Code Using Development Tools
- Don't Use URI Fragments At All!
- Implement a Content Security Policy
-
DOM-based XSS quiz
Three questions. Passing marks the lesson complete.
Sources
- CSP (Content Security Policy) MDN
- Content security policy PortSwigger
- Cross-site scripting PortSwigger
Related lessons
Browse all 45 lessons
Cross-Site Scripting
If your site allows users to add content, you need to be sure that attackers cannot inject malicious JavaScript.
Reflected XSS
When building a website, you need to be sure you do not accidentally create a channel that allows malicious JavaScript to be bounced off your server.
Prototype Pollution
If an attacker can access and modify prototype objects in JavaScript, you are in danger.
CSS Injection
Attackers can manipulate user-generated CSS to extract sensitive data.