XSS (cross-site scripting) is an attack in which someone injects malicious code into a legitimate web page, for example in a comment or a form, so it runs in other visitors' browsers. It can steal sessions, redirect people to fake sites or change what the user sees, and it is prevented by validating and sanitizing everything the site receives.
How TecnetOne handles it: Penetration Testing
cross-site scripting, reflected XSS, stored XSS, DOM XSS