Description:
This occur when attacker input malicious script (e.g. Java Script)
embedded with data input on web application, such as
Username or password field.
Impact:
XSS allows attackers to execute script in the victim’s browser,
which can hijack user sessions, conduct phishing attacks, and
take over the user’s browser using scripting malware.