XSS turns trusted pages into script delivery
The damage is done by the trust the user already has in your page.
Your domain, your session, your certificate. Code running there can read what the user sees, act as them and take their session, and the browser has no reason to object because it genuinely is your page. The attacker has borrowed your reputation with the browser, which is worth far more than anything they could host themselves.
More on Web application security
- CSRF abuses an authenticated browserTheir note, your session
- Output encoding is context-specificThe plug has to match the socket
- Path traversal escapes the intended file areaTwo dots at a time
- File upload security is more than extension checkingThe label is a claim, not a check
- Open redirects lend trusted domains to phishingYour livery, their destination
- Security headers shape browser behaviourInstructions the browser follows
