XSS: Code Review
Modern template engines encode output automatically, which prevents most XSS — until a developer turns that encoding off to render some HTML. Those opt-outs are where stored and reflected XSS hide. This exercise teaches you to review templates and server code for the exact places user data reaches the page as code.
Log in or create a free account to submit keys and track your progress.
What you will learn
- Apply source-to-sink review to output in templates
- Know which template constructs encode by default and which do not
- Spot the "raw/unescaped output" opt-outs that reintroduce XSS
- Tell safe auto-escaped output from unsafe raw output at a glance
Before you start
These exercises cover what this one builds on.
- Cross-Site Scripting (XSS) Medium
- SQL Injection: Code Review Medium
In this exercise
- The sink is the page
- Encoded by default — until it isn't
- Reading for the opt-outs
- Safe vs unsafe at a glance
🔒
This is a Pro exercise
Pro unlocks every exercise, the written solutions, the video walkthroughs and badge certificates. Free exercises stay free.
See Pro plans Create a free account4 sections · 2 keys · 50 points