This lab on Improper Neutralization of Script in Attributes in a Web Page assesses the learner’s understanding of how an existing persistent cross-site scripting vulnerability in the email templates of a cloud-native marketing automation SaaS suite can be discovered and exploited.
Learning Objectives
After completing this lab, the learner will understand how adversaries can exploit such vulnerabilities to:
- Leave malicious payloads that will continue to affect subsequent victims that use the template or receive emails generated by the template.
Framework Connections
Specialty Areas
- Risk Management
- Software Development
Feedback
If you would like to provide feedback for this course, please e-mail the NICCS SO at NICCS@hq.dhs.gov.