Attacker injects a payload in the website’s database with malicious JavaScript that steals cookies. The website transmits to the user’s browser the page with the attacker’s payload and the user’s browsers executes the malicious script. After script execution, the user sends the cookie to the attacker and it’s used for session hijacking.