I asked this question once on SO and never really got a "great" answer I was after.
If my site will only ever allow users to see their own submitted data, and never ever data another user has submitted (i.e. no general 'posts' etc) - then is there actually a XSS risk on my site?
So I'm curious if an attacker can gain anything by looking at their own XSS attack?