cross-site (XSS) vulnerability