Cross-site scripting
Cross-site scripting is getting your code to run inside somebody else's browser session, on a site they trust.
Because it runs on that page, it has the same access the user does: it can read what is on screen, take their session, or act on their behalf while they are logged in. The usual route is content from one user being shown to another without being neutralised first: a comment, a profile name, a support ticket. The user sees an ordinary page on a site they trust, which is exactly what makes it effective.
Checked against the primary source.
