Ensure the X-XSS-Protection header is enabled | CAST Appmarq