About this question
Difference between Self Xss and Reflected XSS.
Difference between Self Xss and Reflected XSS.
Log in to share your answer and help other learners.
Log in to answerBest Answer · By JanBask Cyber Security Expert
Answered on Mar 31, 2022
In both cases, some malicious script is injected in request data and is reflected back to the client's browser. For Reflected XSS, successful exploitation depends on a single HTTP request (GET or POST) which when replayed from the victim's browser (with help of some social engineering), results in script injection. In some cases this may not be possible. Some of the potential reasons for this are:
Presence of a CSRF token
The request with malicious data depends on other previous requests to be successful or has some other prerequisites. The response type for the affected HTTP request is text/json. In this case there would be no script injection if the request is sent on its own because the response is not HTML. In these cases, a successful script injection may be achieved while performing a test from the browser where CSRF token is taken care of, all the prerequisites are met and the text/json response is processed by some other page which mishandles the JSON data. However, it is not possible to develop an exploit that would work on a target machine once the user clicks on a single link. For these reasons, such cases are often termed as "Self XSS". Self XSS would generally be assigned a Low or Informational severity rating due to lack of exploitability.
Free tutorials and interview questions from industry experts — learn the skill, then get ready to prove it.
Step-by-step Cyber Security guides from industry experts
Common Cyber Security interview questions, answered
Guides, tips and career advice on Cyber Security from JanBask experts.
Cyber Security Prepare with 100 Cyber Security Interview Questions & Answers
Boost your interview confidence learn answers to 101 common cybersecurity questions, from basics to advanced techniques.
Cyber Security AI in Cybersecurity: The Double-Edged Sword
Explore how AI is reshaping cybersecurity as a double-edged sword. Learn how attackers use AI for sophisticated threats and how…
Cyber Security Exploring the Advantages and Disadvantages of Ethical Hacking
Discover the key advantages and disadvantages of ethical hacking from enhancing security and regulatory compliance to potential…
Cyber Security Top Cyber Security Projects Ideas to Consider in 2025
Explore 19 practical cybersecurity project ideas for 2025, from AI threat detection to honeypots. Build skills, boost your…