A web scanner reports reflected cross-site scripting in a login form. Which weakness category best explains the finding?
Select an answer to reveal the explanation.
Short Explanation
Think of reflected XSS like a server repeating your words back in the wrong room. If the app doesn't validate input, you type data but the browser runs it as script. Fix validation and encoding before the login page echoes anything.
Full Explanation
Reflected XSS appears when untrusted input is returned in an HTTP response without adequate validation or contextual encoding, allowing the browser to interpret it as active content. Parameters such as error messages, query strings, or form values can be reflected into HTML, JavaScript, or URL contexts. The primary weakness is improper input validation, often paired with output encoding, because the application accepts data and fails to ensure it remains inert in the browser context. Broken authentication concerns credential verification, session handling, or password reset logic, not the execution of reflected script. Insecure direct object reference exposes resources through predictable identifiers, which can lead to unauthorized data access but not script execution. Verbose error disclosure reveals stack traces or internal details, aiding reconnaissance rather than creating a browser scripting sink. Exam caveat: reflected XSS may be reported by scanners even when a parameter is merely echoed, so confirm the sink and browser execution context before remediation. Operational check: fuzz response parameters with benign HTML and script payloads, then verify that user input is validated, encoded for the exact output context, and never interpreted as active content.