Description
This issue has been retired in favour of X-XSS-Protection Header is Set
The HTTP X-XSS-Protection response header is a feature of Internet Explorer, Chrome and Safari that stops pages from loading when they detect reflected cross-site scripting (XSS) attacks. Mozilla
Recommendation
Configure your server to send this header for all pages. You can see references for possible values.
References
Could your website be exposed too?
SmartScanner can check your website for X-XSS-Protection Header is Missing and gives you actionable findings to investigate.
Start a free scanRelated Issues
- Content-Security-Policy Header is Missing - Vulnerability
- X-XSS-Protection Header is Set - Vulnerability
- X-Frame-Options Header is Missing - Vulnerability
- X-Content-Type-Options Header is Missing - Vulnerability


