In the 21st century, UTF-8 became de facto the standard for www. In order to not overwrite thousands of http-server, it's enough to change "text/html" to "text/html;charset=UTF-8" in mime-types by ...
When serving static utf-8 encoded html pages with Asp.Net Core's UseStaticFiles, the response ContentType is set to text/html and not text/html; charset=utf-8 ...
Based on this small portion of the HTTP response, you can assume that this web application is likely prone to an XSS vulnerability. HTTP/1.1 200 OK Server: Some Server Content-Type: text/html; ...