Cross-Site Script Inclusion
By Malcolm McDonald Founder, Editor-in-ChiefAuthor of Grokking Web Application Security
If you are putting sensitive data in your JavaScript files, an attacker is probably stealing it.
- Prevalence
- Occasional
- Exploitability
- Easy
- Impact
- Harmful
What is cross-site script inclusion (XSSI)?
Cross-site script inclusion (XSSI) is a cross-origin data theft attack in which a malicious website loads a JavaScript file from your domain using a script tag. Browsers do not apply the same-origin policy to script imports, so if the file contains sensitive data about a logged-in user, the attacker's page can read and steal it.
What you'll learn
- Why script imports are not covered by the same-origin policy
- How a malicious page reads sensitive data from your JavaScript files
- How to load user state from a JSON URL instead
This lesson includes
-
Cross-Site Script Inclusion lab
Script files aren't covered by the same-origin policy, so any site can import yours. See what that means for a single-page app that writes each user's API key into its JavaScript: a malicious page imports the file and reads the key.
-
How to prevent Cross-Site Script Inclusion
The prevention guide covers two approaches:
- Don't Interpolate Sensitive Data in JavaScript Files
- Load Page State from a JSON URL
-
Cross-Site Script Inclusion quiz
Two questions. Passing marks the lesson complete.
Sources
- CWE-200 MITRE
Related lessons
Browse all 45 lessons
Cross-Origin Resource Sharing
Overly permissive CORS policies can allow malicious websites to access your APIs and steal user data.
Cross-Site Request Forgery
If an attacker can forge HTTP requests to your site, they may be able to trick your users into triggering unintended actions.
Cross-Site Scripting
If your site allows users to add content, you need to be sure that attackers cannot inject malicious JavaScript.
Information Leakage
Revealing system information helps an attacker learn about your tech stack.