JSP authentication bypass


Manual confirmation is required for this alert.

Your web application is restricting access to this .jsp file using Basic Authentication. It looks like Acunetix WVS managed to bypass this restriction by replacing the .jsp extension with .jsp;.css.


Review your authentication rules and make sure that files that end with .jsp;.css cannot bypass the authentication.