A mental model of XSS attack

Lesson#3 of 12 in project Theory

Mental Model Difference

Stored XSS

💣 You leave a bomb in the app.

Reflected XSS

🎣 You send a poisoned link.

DOM XSS

🪞 The frontend poisons itself using user-controlled data.