השיעור הזה זמין כרגע באנגלית.
When a comment runs code
Cross-site scripting (XSS) lets an attacker run their JavaScript inside your page, in your users' browsers, with your users' sessions. It is one of the most common web bugs, and it often starts with a single innerHTML.