Cross-Site Scripting (XSS) attacks inject malicious scripts into trusted websites, which are then executed in the victim's browser. Therefore, the primary direct target of an XSS attack is the end user rather than the server or application framework.