The product does not neutralize or incorrectly neutralizes web scripting syntax in HTTP headers that can be used by web browser components that can process raw headers, such as Flash.
Perform output validation in order to filter/escape/encode unsafe data that is being passed from the server in an HTTP response header.
Disable script execution functionality in the clients' browser.
Our security experts can help you identify and remediate CWE-644 vulnerabilities in your codebase.
Get Security Assessment