Vulnerabilities/

X-XSS-Protection Header is Missing

Impact: Informational

Description

This issue has been retired in favour of X-XSS-Protection Header is Set

The HTTP X-XSS-Protection response header is a feature of Internet Explorer, Chrome and Safari that stops pages from loading when they detect reflected cross-site scripting (XSS) attacks. Mozilla

Recommendation

Configure your server to send this header for all pages. You can see references for possible values.

References

Last updated on November 10, 2021

Order SmartScanner Professional version

See Pricing