Skip to content
ScopefileGet the app

Technique fileHacking web applications

XSS vs CSRF vs SSRF: whose context runs the request

XSS runs attacker script inside the victim's browser, CSRF makes the victim's browser send a request the user never chose, and SSRF makes the server send a request to a destination the attacker picked. The question that separates them: whose machine issues the harmful request, and on whose authority?

Exam
312-50
Domain
5 · Web apps
Targets
9

Who sends what, to whom

The script-injection and request-forgery flaws from Module 14
TraitXSSCSRFSSRF
Runs in (differs)The victim's browser, as the trusted siteThe victim's browser, with the victim's cookiesThe application server
Attacker supplies (differs)Script content the site stores or echoesA page or link that triggers a requestAn address the server will fetch
Trust being abused (differs)The browser trusts the site's pagesThe site trusts the browser's credentialsInternal systems trust the server
Typical prize (differs)Session data, page content, keystrokesA state change: email, password, paymentInternal services, cloud metadata
Attacker reads the response (differs)Yes, the script runs in the pageNo, the forgery is blindSometimes, sometimes blind
Main defense family (differs)Encoding output for its contextUnpredictable per-request tokensRestricting what the server may fetch
OWASP 2021 home (differs)A03 InjectionA01 Broken Access ControlA10 SSRF
OWASP 2025 home (differs)A05 InjectionA01 Broken Access ControlA01 Broken Access Control

Tinted rows marked ≠: at least one of the 3 differs from the others.

OWASP homes checked on owasp.org on Oct 11, 2026. The CEH v13 course outline still names the 2021 edition.

What defines each one

XSS: where the script lives

Stored XSS keeps the script inside the application, so later visitors run it. Reflected XSS bounces it off a single request, so the victim has to follow a crafted link. DOM-based XSS is a flaw in how the page's own scripts handle untrusted data. In every variant the browser treats the script as the site's own code, which is why it can read what the site can read.

CSRF: an action the user did not choose

CSRF needs three things: a logged-in victim, a state-changing request the site accepts on the strength of the session cookie alone, and nothing unpredictable in that request. Remove any one and the forgery fails, which is why per-request tokens and re-authentication for high-value actions are the standard answers.

SSRF: a server that fetches on request

Any feature that makes the server retrieve something from a supplied address (link previews, file imports, integrations) can be pointed at places the outside world cannot reach. In cloud environments the usual target is the instance metadata service, which ties this flaw to the cloud computing module.

One quick separator: CSRF only works against a victim with an active session, while XSS and SSRF do not depend on one. SQL injection is the other big injection topic in this part of the blueprint; SQL injection types sorts it, and the web application hacking module covers the rest of Module 14.

Browser or server?

Three flaws and one recurring question: where does the harmful request start, and whose authority does it carry?

Answered 0/9Hits 0

T-01

What type of XSS attack occurs when malicious scripts are permanently stored on target servers and executed when users access the stored information?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. ACorrect: stored, or persistent, XSS saves the malicious script on the server, for example in a comment, so it runs for every visitor who views it.
  2. BDOM-based XSS arises in client-side JavaScript that writes untrusted data into the page, without the payload being stored on the server.
  3. CInduced XSS is not a standard category; the recognized types are stored, reflected and DOM-based.
  4. DReflected XSS echoes the script back from the current request, such as a crafted link, without storing it on the server.
T-02

In a DOM-based XSS attack, where does the vulnerability exist?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. AServer-side flaws produce stored or reflected XSS, while DOM-based XSS can occur even if the server response is safe.
  2. BCorrect: DOM-based XSS lives in client-side JavaScript that passes untrusted input, such as the URL fragment, into dangerous sinks like innerHTML.
  3. CDatabase query flaws lead to SQL injection, not DOM-based cross-site scripting.
  4. DHTTP headers can carry attack data, but DOM-based XSS is defined by unsafe handling in the browser's page scripts.
T-03

A threat actor injects malicious JavaScript into a forum profile description. Whenever other users view the profile, the script executes to steal session tokens. How does this attack primarily differ from SQL injection?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. AChanging backend query structure describes SQL injection, not the stored XSS shown in the scenario.
  2. BWeak security headers can make XSS worse, but the attack is enabled by unescaped user input, not exclusively by misconfiguration.
  3. CStealing session tokens targets other users' sessions in their browsers rather than attacking the server's authentication logic directly.
  4. DCorrect: XSS runs attacker script in other users' browsers, while SQL injection runs attacker-controlled queries against the backend database.
T-04

A team implements a strict Content Security Policy (CSP) to mitigate a reflected XSS vulnerability. While the CSP prevents payload execution, the underlying injection flaw remains. How should this architectural decision be evaluated?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. AContext-aware output encoding is still the primary fix, because CSP can be misconfigured, bypassed or unsupported.
  2. BCSP is a browser-side mitigation and does not replace server-side validation and encoding of untrusted data.
  3. CCorrect: CSP adds a valuable second layer that limits script execution, but the injection flaw must still be fixed with proper output encoding.
  4. DThe vulnerable code remains, so CSP mitigates impact without removing the root cause.
T-05

Which web application attack forces authenticated users to submit unwanted requests to a web application where they are currently authenticated?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. ACorrect: CSRF abuses a victim's existing authenticated session, tricking their browser into sending unwanted requests to a site they are logged in to.
  2. BXSS injects scripts into pages that run in the victim's browser, while CSRF forges requests without needing to inject code.
  3. CSSRF tricks the server into making requests to destinations of the attacker's choosing, not the user's browser.
  4. DSession hijacking steals or predicts a session token to impersonate a user, rather than making the user's browser send forged requests.
T-06

An application relies entirely on the SameSite=Lax cookie attribute to prevent cross-site request forgery. Under which circumstance does this defense mechanism fundamentally fail to protect authenticated users?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. AContent Security Policy controls which resources a page may load and does not weaken or strengthen SameSite cookie behavior.
  2. BCorrect: SameSite depends on browser enforcement, so legacy browsers that ignore it send cookies cross-site; Lax also allows top-level GET navigations.
  3. CUsing HTTPS everywhere is good practice but has no effect on whether cookies are sent with cross-site requests.
  4. DTokens kept in session storage are not sent automatically, so they are not exposed to classic CSRF in the first place.
T-07

What vulnerability allows attackers to extract sensitive information by manipulating an application into sending HTTP requests to arbitrary destinations?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. ACorrect: SSRF makes the server issue requests to destinations the attacker picks, such as internal services or cloud metadata endpoints.
  2. BCSRF makes the victim's browser send requests to a trusted site, not the server to arbitrary destinations.
  3. CXXE abuses XML parsers that resolve external entities; it can trigger SSRF but is a distinct parser vulnerability.
  4. DAn open redirect sends the user's browser elsewhere, so the request comes from the client rather than the server.
T-08

An application accepts a user-provided URL parameter. Upon submission, you capture an HTTP 302 response directing your browser to the supplied external URL. Why does this behavior indicate an Open Redirect rather than an SSRF?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. AA 302 status does not by itself block access to metadata services; what matters is who makes the follow-up request.
  2. BLocation headers do not enforce any origin policy; they simply tell the browser where to go next.
  3. CServer-side requests built from unsanitized input describe SSRF, which is the opposite of what a 302 to the browser shows.
  4. DCorrect: a 302 tells the user's browser to fetch the new URL, so the request originates on the client, while SSRF requests come from the server.
T-09

A development team must remediate a severe Server-Side Request Forgery (SSRF) vulnerability found in a webhook feature. Which server-side control is the MOST effective mitigation against this attack vector?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. ADenylists of private ranges are easily bypassed with alternate IP encodings, DNS rebinding or redirects, so they are weaker than allowlists.
  2. BContent Security Policy governs what a browser may load and has no effect on requests the server itself makes.
  3. CCorrect: a strict allowlist of permitted destinations, plus blocking redirects and re-validating resolved addresses, is the most robust SSRF control.
  4. DAnti-CSRF tokens prove a request came from the legitimate user's session but do not restrict where the server sends outbound requests.

What to drill next in Module 14

  • The three XSS variants and where the script sits in each.
  • The three conditions CSRF needs, and which defense removes which.
  • Server features that fetch URLs, and why internal networks trust them.
  • Directory traversal against file inclusion against command injection, the next look-alike set.
  • Which OWASP edition your study material quotes.

Sources