【软件安全】什么是XSS(Cross-Site Scripting,跨站脚本)?EN: XSS (Cross-Site Scripting) is a web vulnerability where an attacker injects untrusted JavaScript into a page so that it runs in other users’ browsers. With the victim’s session, the script can steal cookies/tokens, hijack accounts, deface UI, or pivot