Let’s say you have an input-based navigation system like so:


<h1>Bob's Books</h1>
<div id="default">
<p><i>Where would you like to go?</i></p>
<input id="location" type="text" placeholder="Where would you like to go?">
<button id="go">Go!</button>
<div id="result" hidden>
<!-- ... -->
<!-- Elements with spans for things like name, image, etc. that have IDs handled in script -->
// ...
// <span>.innerHTML = <requestedLocation>;

Now, this would be great, right? … Not so much.

If a malicious person wanted to execute scripts messing with databases, importing scripts, etc., they would type something like this:

<script>function goodbyeBob(){/*...*/}</script><img src onerror="goodbyeBob()"/>

And, since innerHTML allows HTML, all of that malicious JavaScript code would get executed heartily.

How To Fix

Change all references to innerHTML from user-input to innerText. If you want SOME HTML features to be able to be entered by the user and executed (preferrably filtered), use .replace(), if ... else, guard clauses, etc.