The configuration for X-XSS-Protection on the Liferay side is defined atsystem.properties. The default setting is "1", which enables filtering on the browser side. It is believed that the content has been sanitized because it has been determined to be vulnerable on the browser side
It is possible that the behavior may vary from browser to browser.Please also check the behavior of different browsers