The URI path directory after /portal is vulnerable to reflected cross-site scripting. By visiting the following URI, a javaScript pop-up will appear when the mouse is moved over the minimize/maximize buttons. Note this issue is only reproduced on firefox browser. This rule supports to defend the A6: Vulnerable and Outdated Components of OWASP Top 10 - 2021. Other reference:None