See: BeEF (Browser Exploitation Framework)

A website is vulnerable to XSS when user input is not properly sanitized and is then displayed as part of the webpage, giving an attacker a chance to inject code.