Sign Up

Sign Up to our social questions and Answers Engine to ask questions, answer people’s questions, and connect with other people.

Have an account? Sign In

Have an account? Sign In Now

Sign In

Login to our social questions & Answers Engine to ask questions answer people’s questions & connect with other people.

Sign Up Here

Forgot Password?

Don't have account, Sign Up Here

Forgot Password

Lost your password? Please enter your email address. You will receive a link and will create a new password via email.

Have an account? Sign In Now

You must login to ask a question.

Forgot Password?

Need An Account, Sign Up Here

Please briefly explain why you feel this question should be reported.

Please briefly explain why you feel this answer should be reported.

Please briefly explain why you feel this user should be reported.

Sign InSign Up

The Archive Base

The Archive Base Logo The Archive Base Logo

The Archive Base Navigation

  • Home
  • SEARCH
  • About Us
  • Blog
  • Contact Us
Search
Ask A Question

Mobile menu

Close
Ask a Question
  • Home
  • Add group
  • Groups page
  • Feed
  • User Profile
  • Communities
  • Questions
    • New Questions
    • Trending Questions
    • Must read Questions
    • Hot Questions
  • Polls
  • Tags
  • Badges
  • Buy Points
  • Users
  • Help
  • Buy Theme
  • SEARCH
Home/ Questions/Q 7818411
In Process

The Archive Base Latest Questions

Editorial Team
  • 0
Editorial Team
Asked: June 2, 20262026-06-02T06:34:00+00:00 2026-06-02T06:34:00+00:00

If my site will only ever allow users to see their own submitted data,

  • 0

If my site will only ever allow users to see their own submitted data, and never ever data another user has submitted (i.e. no general ‘posts’ etc) – then is there actually a XSS risk on my site?

I’m still going to work towards XSS solutions (like httmlspecialchars() etc) – but I’m curious if an attacker can gain anything by looking at their own XSS attack?

  • 1 1 Answer
  • 0 Views
  • 0 Followers
  • 0
Share
  • Facebook
  • Report

Leave an answer
Cancel reply

You must login to add an answer.

Forgot Password?

Need An Account, Sign Up Here

1 Answer

  • Voted
  • Oldest
  • Recent
  • Random
  1. Editorial Team
    Editorial Team
    2026-06-02T06:34:01+00:00Added an answer on June 2, 2026 at 6:34 am

    An attacker cannot gain anything by using cross-site scripting techniques on themselves. The intent of cross-site scripting is to manipulate page elements displayed to the user in a malicious way, be it phishing or reading a cookie. In other words, the attack can only affect client-side entities.

    However, it is important to keep in mind what “user only ever looking at their own data” means.

    Suppose I have a website where users can have a private profile, viewable only to themselves. There is a text input element on the page that allows users to enter their website URL. Now suppose the form to update a user’s profile uses GET.

    A page update submission might look like this:

    http://www.example.com/privateprofile.pl?action=update&userwebpage=http://www.example.net

    An attacker might exploit this by tricking the user into loading the URL:

    http://www.example.com/privateprofile.pl?action=update&userwebpage=[malicious_js_code_here]

    This is a fairly trivial example, of course, but hopefully it demonstrates the general concept. The concern is that there is the possibility that they may be able to trick the user into entering the XSS themselves. Of course, the viability of an XSS attack like this depends on your specific implementation.

    • 0
    • Reply
    • Share
      Share
      • Share on Facebook
      • Share on Twitter
      • Share on LinkedIn
      • Share on WhatsApp
      • Report

Sidebar

Related Questions

I have a timer on the site which the user will only be able
I have a site that will require a login by the users. The client
I am working an e-commerce site which will allow pdfs to be downloaded once
I have a Search box on my site and when ever the user types
I am using cakephp 2.0 for developing a website. Site will contain only 2
If my site ever goes live (don't think it will, its just a learning
I'm developing a site that has a few files on it that I only
I notice on bad quality websites with ads a piece of the site will
I'm developing an online store with Magento. The site will be high traffic and
HELP!! I need to bundle a gem otherwise a published client's site will stay

Explore

  • Home
  • Add group
  • Groups page
  • Communities
  • Questions
    • New Questions
    • Trending Questions
    • Must read Questions
    • Hot Questions
  • Polls
  • Tags
  • Badges
  • Users
  • Help
  • SEARCH

Footer

© 2021 The Archive Base. All Rights Reserved
With Love by The Archive Base

Insert/edit link

Enter the destination URL

Or link to existing content

    No search term specified. Showing recent items. Search or use up and down arrow keys to select an item.