In more detail
It happens when user input is placed in a page without being escaped, for example a comment containing a <script> tag. A script that runs can read cookies, change the page or act as the user. Defences: escape output for its context (see HTML Entity Encode), use a strict Content Security Policy (CSP), mark session cookies HttpOnly and prefer frameworks that escape by default.