What can an attacker do?

  • Self-XSS / Reflected XSS / Non-persistent XSS / Type-II XSS
  • Persistent XSS / Stored XSS / Type-I XSS
  • DOM based XSS


Self-XSS Example

A summary

This article was published in 2015, so it doesn’t reflect the current state of things but you can read the 2019 update.

Michele Preziuso

