Script injection
Someone tries to plant a script in one of your pages.
What it is
Script code sent as if it were ordinary text, hoping your site shows it back to other visitors, whose browsers would then run it.
- <script> in a comment
- An image tag with an onerror handler
- A link that starts javascript:
Why it matters
A planted script acts as the visitor: it can take over their session, change what the page says, or send them somewhere else.
If a real visitor is ever stopped
Editors that save HTML, such as a page builder or a blog's writing screen, send real markup that looks like this. Mark the request as real and that one field is let through.