Search code examples
asp.netxssowasp

Is Persistent XSS and Stored XSS are EXACLY Same?


Can I safely assume that Stored XSS is not Subset OR Superset to Persistent XSS and they mean exactly the same thing. If different Please suggest few links to read further on this in Dotnet Web applications context.


Solution

  • Yes.

    See https://www.owasp.org/index.php/Types_of_Cross-Site_Scripting : "Stored XSS (AKA Persistent or Type I)"

    Here's a good technology independent description of XSS: https://www.owasp.org/index.php/Cross-site_Scripting_(XSS)

    There's also this on the MS site: https://learn.microsoft.com/en-us/aspnet/core/security/cross-site-scripting but I dont use dotnet so cant vouch for its content.