What type of XSS attack occurs when malicious scripts are permanently stored on target servers and executed when users access the stored information?
Make the call. Every option has a note waiting here.
Notes on all 4 options
- ACorrect: stored, or persistent, XSS saves the malicious script on the server, for example in a comment, so it runs for every visitor who views it.
- BDOM-based XSS arises in client-side JavaScript that writes untrusted data into the page, without the payload being stored on the server.
- CInduced XSS is not a standard category; the recognized types are stored, reflected and DOM-based.
- DReflected XSS echoes the script back from the current request, such as a crafted link, without storing it on the server.