Courseiva
Vulnerability Management →mediumMultiple Choice

CS0-003 Vulnerability Management Practice Question

A vulnerability scanner reports a plugin that identifies a web application vulnerability related to the failure to validate user input, allowing an attacker to inject malicious scripts that execute in other users' browsers. Which OWASP Top 10 category does this vulnerability fall under?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Injection

The description matches cross-site scripting (XSS), which is part of the OWASP Top 10 category 'Injection' (formerly separate, but in 2021 XSS is included in Injection).

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Injection

    Why this is correct

    Injection vulnerabilities occur when untrusted user input is interpreted as part of a command or query, leading to unauthorized execution. In OWASP frameworks, Cross-Site Scripting (XSS) is classified as a form of injection because malicious scripts are injected into trusted web applications to execute in the victim's browser.

  • ✗

    Security Misconfiguration

    Why it's wrong here

    Security Misconfiguration refers to weaknesses arising from default accounts, unpatched features, enabled debug modes, or overly permissive CORS headers. While it represents a significant threat vector, it does not describe the specific mechanism of injecting malicious payloads or scripts into input fields to manipulate application logic.

  • ✗

    Cryptographic Failures

    Why it's wrong here

    Cryptographic Failures, formerly known as Sensitive Data Exposure, involve the inadequate protection of data in transit or at rest, such as using weak hashing algorithms or outdated TLS protocols. This category is unrelated to input validation flaws that allow attackers to execute arbitrary scripts or commands within a web application.

  • ✗

    Broken Access Control

    Why it's wrong here

    Broken Access Control occurs when an application fails to properly enforce authorization policies, allowing users to access resources or perform actions outside their intended privileges. This flaw involves privilege escalation or bypassing access checks, rather than the execution of injected malicious payloads in a user's browser session.

Go deeper

Related to this question

About these practice questions

One of 701 original CS0-004 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.