What is Cross-Site Scripting (XSS)?
- A.A network routing problem, on the basis that a significant change requires rescanning only of the component that was changed for SAQ A merchants
- B.An attack where malicious scripts are injected into web pages viewed by other users, potentially stealing session data or cardholder information
- C.A database error, which Requirement 3.2.1 subjects to documented retention limits and a process at least every three months to find and securely delete anything exceeding them
- D.A server configuration issue, given that the standard requires separation of duties only between developers and assessors for SAQ A-EP merchants
Why B is correct
XSS allows attackers to inject malicious scripts into web pages, which execute in other users' browsers, potentially stealing session data or cardholder information.
Know someone studying for PCI DSS? Send them this one.