I am using Less-1.5.1.js in an old application. A recent Checkmarx static security scan flagged the following code as a "forced browsing" vulnerability, based on t