A web attack in which harmful scripts are injected into pages that other users then view; a WAF blocks it.
Also called cross-site scripting.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains XSS in context, with comparison tables and the common traps.
Terms in this definition
- View
Shows a system through one chosen group of related concerns. No view is generic; each one is tied to whichever architecture it depicts.
- Web Application Firewall
Protection at layer 7 from OWASP Top 10 threats like XSS and SQL injection, available on Application Gateway or Front Door.
Related terms
- DRS
The Default Rule Set, Microsoft's managed WAF rules that succeed OWASP CRS and defend against XSS, SQL injection and other frequent attacks. Single rules may be overridden or switched off.