Answer:
An attacker can use XSS to steal user cookies and session tokens by injecting a malicious script that captures the cookies and sends them to an external server controlled by the attacker.
An attacker can use XSS to steal user cookies and session tokens by injecting a malicious script that captures the cookies and sends them to an external server controlled by the attacker.
You may be interested in:
Web Security MCQs