cross-site scripting flaw