Curious how would other security personnel take “x-content-type-missing” in a non-public facing web UI as ? This is something I considered as a very minor issue since a server (which has UI) is not essentially exposed to Public. But a senior security engineer from a reputed pentest company thinks otherwise as medium vulnerability ! May be I am wrong (always learning) but thought to get some opinion here.