XSS turns trusted pages into script delivery

The damage is done by the trust the user already has in your page.

Your domain, your session, your certificate. Code running there can read what the user sees, act as them and take their session, and the browser has no reason to object because it genuinely is your page. The attacker has borrowed your reputation with the browser, which is worth far more than anything they could host themselves.

More on Web application security