The one-sentence version
XSS means the application takes attacker-controlled text and later renders it as HTML or JavaScript in someone else''s browser. The difference between reflected and stored is only where that text lives.
| Type | Where the payload lives | Typical lab clue |
|---|---|---|
| Reflected | In the request (query, form) and bounced back in the response | Search box echoes your string |
| Stored | Saved in the database (comment, profile, ticket) | Your string shows up for the next visitor |
What to try in a lab
- Submit a unique marker like XSSPROBE123 and see if it comes back unescaped.
- View page source — if you see raw angle brackets, the sink is HTML.
- For stored XSS, log out and load the page as another test user.
Code
html<p>Results for: USER_INPUT</p>Defense
Escape on output for the right context (HTML body vs attribute vs JS). A Content-Security-Policy is extra defense, not a substitute for encoding.
Why labs still matter
Frameworks reduced accidental XSS, but template bypasses, markdown, and rich-text widgets still create sinks. A lab lets you see the response, not just read a definition.