The same-origin policy doesn't prevent XSS attacks very well. Instead, we need to use Content Security Policy. Here is an example.
An Attack Prevented by CSP
An Attack Prevented by CSP
An Attack Prevented by CSP
The same-origin policy doesn't prevent XSS attacks very well. Instead, we need to use Content Security Policy. Here is an example.