Disabled X-XSS-Protection Header
Invicti detected a disabled
X-XSS-Protection header which means that this website could be at risk of a Cross-site Scripting (XSS) attacks.
Internet Explorer's built-in cross-site scripting protection can be disabled by using the following HTTP Header :
X-XSS-Protection: 1; mode=block
Please also be advised that in some specific cases enabling XSS filter can be abused by attackers. However, in most cases, it provides basic protection for users against XSS attacks.