What is DOM XSS and why should you care?

Josh Hickling · Computer Fraud & Security · 2021

For more than 10 years, cross-site scripting (XSS) has been included in OWASP's ‘Top 10 Web Application Security Risks’. 1 Although the issue is very well documented, it is sometimes overlooked by application owners. As a result, penetration testers frequently encounter this vulnerability, which takes several forms. For more than 10 years, cross-site scripting (XSS) has been included in OWASP's top web application security risks. Yet it's an issue that is often overlooked. The problem has also evolved and many people still do not understand the risks surrounding Document Object Model (DOM) or client-side XSS. Through understanding the vector itself, threat surfaces of applications will become ever-more restricted and safer for the end user. A thorough understanding of DOM-based XSS will help balance the scales of application security and usability, says Josh Hickling of Pentest People.

Read the paper · More papers on PaperTik