Reflected XSS
By Malcolm McDonald Founder, Editor-in-ChiefAuthor of Grokking Web Application Security
When building a website, you need to be sure you do not accidentally create a channel that allows malicious JavaScript to be bounced off your server.
- Prevalence
- Common
- Exploitability
- Easy
- Impact
- Harmful
What is reflected XSS?
Reflected XSS is a cross-site scripting (XSS) attack, a type of injection attack, in which malicious JavaScript in an HTTP request is echoed back in the response. The attacker puts the script in a link, usually a query parameter, and tricks a victim into clicking it. The script then runs in the victim's browser with the privileges of your site.
What you'll learn
- How a script in a request gets echoed back and run in a victim's browser
- Which pages are most likely to reflect user input
- How escaping dynamic content and a Content Security Policy stop the attack
Where this lesson counts
OWASP Top 10
Untrusted input reaches an interpreter as part of a command or query, including SQL, OS and cross-site scripting.
OWASP 2025 folds cross-site scripting into Injection: untrusted input reaching the HTML interpreter.
Learn more about A05PCI DSS 4.0
Requirement 6.2.4: engineering techniques must prevent injection, data-structure, cryptographic, business-logic and access-control attacks in bespoke software.
Learn more about 6.2.4Requirement 6.4.1: public-facing web applications must be protected against known attacks by regular vulnerability review or an automated technical solution.
Learn more about 6.4.1This lesson includes
-
Reflected XSS lab
Mal notices that a restaurant review site echoes search terms back without escaping them. Watch him build a search URL containing a script, email it to Vic and collect Vic's session ID from his server log after the redirect.
-
How to prevent Reflected XSS
The prevention guide covers three approaches:
- Escape Dynamic Content
- Allowlist Values
- Implement a Content Security Policy
-
Reflected XSS quiz
Three questions. Passing marks the lesson complete.
Sources
- CSP (Content Security Policy) MDN
- Content security policy PortSwigger
- Cross-site scripting PortSwigger
Related lessons
Browse all 45 lessons
Cross-Site Scripting
If your site allows users to add content, you need to be sure that attackers cannot inject malicious JavaScript.
DOM-based XSS
If you make use of URI fragments in your site, you need to ensure they cannot be abused to inject malicious JavaScript.
Open Redirects
Most web-applications make use of redirects. If your site forwards to URLs supplied in a query string, you could be enabling phishing attacks.
Cross-Site Request Forgery
If an attacker can forge HTTP requests to your site, they may be able to trick your users into triggering unintended actions.