Skip to content

Topic

HTML and script injection

Class of software flaw in which untrusted input is written into a page without escaping, so a browser treats it as markup or executable code instead of text.

Current clusters