XSS: Code Review

🔒 Pro Medium Code review Online Avg. time 30 min Solved by 0 2 keys · 50 pts Code Review

Modern template engines encode output automatically, which prevents most XSS — until a developer turns that encoding off to render some HTML. Those opt-outs are where stored and reflected XSS hide. This exercise teaches you to review templates and server code for the exact places user data reaches the page as code.

Skills covered: Code ReviewXSS
Log in or create a free account to submit keys and track your progress.

What you will learn

  • Apply source-to-sink review to output in templates
  • Know which template constructs encode by default and which do not
  • Spot the "raw/unescaped output" opt-outs that reintroduce XSS
  • Tell safe auto-escaped output from unsafe raw output at a glance

Before you start

These exercises cover what this one builds on.

In this exercise

  1. The sink is the page
  2. Encoded by default — until it isn't
  3. Reading for the opt-outs
  4. Safe vs unsafe at a glance
🔒

This is a Pro exercise

Pro unlocks every exercise, the written solutions, the video walkthroughs and badge certificates. Free exercises stay free.

See Pro plans Create a free account

4 sections · 2 keys · 50 points