The Burp Suite User Forum was discontinued on the 1st November 2024.

Burp Suite User Forum

For support requests, go to the Support Center. To discuss with other Burp users, head to our Discord page.

SUPPORT CENTER DISCORD

Incorrect Issue Type/Advisory Finding & Remediation

grace | Last updated: Jul 27, 2021 09:28PM UTC

Issue:  Browser cross-site scripting filter disabled This issue is incorrect. The remediation says to use "X-XSS-Protection: 1; mode=block" but according to OWASP "The X-XSS-Protection header has been deprecated by modern browsers and its use can introduce additional security issues on the client side. As such, it is recommended to set the header as X-XSS-Protection: 0" Reference https://owasp.org/www-project-secure-headers/#x-xss-protection This issue should be fixed in the app.

Uthman, PortSwigger Agent | Last updated: Jul 28, 2021 08:42AM UTC