This project demonstrates a professional security assessment performed on a live web application to identify Cross-Site Scripting (XSS) vulnerabilities. The testing was conducted in an authorized environment following ethical security practices.
To evaluate the application's resilience against:
Reflected XSS
Stored XSS
DOM-Based XSS
Target: Live Web Application (Authorized Testing)
Module Tested: Contact Form
Input Fields:
Full Name
Email Address
hone Number
Message Field
Web Browser (Google Chrome)
Browser Developer Tools
Manual Payload Testing
The assessment followed a structured approach:
Input Field Identification
Payload Injection
Response Analysis
Execution Validation
<script>alert(1)</script> <script>alert('stored')</script>
This screenshot shows all user input fields discovered during testing.
Payload entered in Name and Message fields.
No popup was observed. Input was not executed.
Payload entered in Name and Message fields.
No popup was observed. Input was not executed.
Input may be stored but not executed. No stored XSS found.
Test Type Result
Reflected XSS - Not Vulnerable
Stored XSS - Not Vulnerable
DOM-Based XSS - Not Vulnerable
Input validation is properly implemented Script payloads are not executed No reflection of malicious input in response Application demonstrates secure input handling
The application is not vulnerable to basic XSS attacks in the tested scope. Proper validation and secure coding practices effectively prevent script execution.
Implement output encoding Apply strict input validation Use Content Security Policy (CSP) Conduct regular security testing
This project provided hands-on experience in testing real-world applications and understanding how modern applications defend against XSS attacks.
This assessment was conducted with proper authorization. No harmful or intrusive actions were performed.
Abhishek Yewale Cybersecurity Enthusiast | VAPT | OWASP Top 10



