VYPR

CWE-602

Client-Side Enforcement of Server-Side Security

ClassDraftLikelihood: Medium

Description

The product is composed of a server that relies on the client to implement a mechanism that is intended to protect the server.

When the server relies on protection mechanisms placed on the client side, an attacker can modify the client-side behavior to bypass the protection mechanisms, resulting in potentially unexpected interactions between the client and server. The consequences will vary, depending on what the mechanisms are trying to protect.

Hierarchy (View 1000)

Parents

Related attack patterns (CAPEC)

CAPEC-162 · CAPEC-202 · CAPEC-207 · CAPEC-208 · CAPEC-21 · CAPEC-31 · CAPEC-383 · CAPEC-384 · CAPEC-385 · CAPEC-386 · CAPEC-387 · CAPEC-388

CVEs mapped to this weakness (164)

page 6 of 9
  • CVE-2025-23041MedJan 14, 2025
    risk 0.38cvss 5.8epss 0.00

    Umbraco.Forms is a web form framework written for the nuget ecosystem. Character limits configured by editors for short and long answer fields are validated only client-side, not server-side. This issue has been patched in versions 8.13.16, 10.5.7, 13.2.2, and 14.1.2. Users are…

  • CVE-2025-41402MedOct 23, 2025
    risk 0.36cvss 5.5epss 0.00

    Client-Side Enforcement of Server-Side Security (CWE-602) in the Command Centre Server allows a privileged operator to enter invalid competency data, bypassing expiry checks. This issue affects Command Centre Server:  9.30 prior to vEL9.30.2482 (MR2), 9.20 prior to…

  • CVE-2024-41751MedJul 23, 2025
    risk 0.36cvss 5.5epss 0.00

    IBM SmartCloud Analytics - Log Analysis 1.3.7.0, 1.3.7.1, 1.3.7.2, 1.3.8.0, 1.3.8.1, and 1.3.8.2 could allow a local, authenticated attacker to bypass client-side enforcement of security to manipulate data.

  • CVE-2024-41750MedJul 23, 2025
    risk 0.36cvss 5.5epss 0.00

    IBM SmartCloud Analytics - Log Analysis 1.3.7.0, 1.3.7.1, 1.3.7.2, 1.3.8.0, 1.3.8.1, and 1.3.8.2 could allow a local, authenticated attacker to bypass client-side enforcement of security to manipulate data.

  • CVE-2023-3747MedSep 7, 2023
    risk 0.36cvss 5.5epss 0.00

    Zero Trust Administrators have the ability to disallow end users from disabling WARP on their devices. Override codes can also be created by the Administrators to allow a device to temporarily be disconnected from WARP, however, due to lack of server side validation, an attacker…

  • CVE-2017-14013MedOct 17, 2017
    risk 0.36cvss 5.6epss 0.01

    A Client-Side Enforcement of Server-Side Security issue was discovered in ProMinent MultiFLEX M10a Controller web interface. The log out function in the application removes the user's session only on the client side. This may allow an attacker to bypass protection mechanisms,…

  • CVE-2026-27611MedFeb 25, 2026
    risk 0.35cvss 6.5epss 0.00

    FileBrowser Quantum is a free, self-hosted, web-based file manager. Prior to versions 1.1.3-stable and 1.2.6-beta, when users share password-protected files, the recipient can completely bypass the password and still download the file. This happens because the API returns a…

  • CVE-2023-23570MedDec 18, 2023
    risk 0.35cvss 5.4epss 0.01

    Client-Side enforcement of Server-Side security for the Command Centre server could be bypassed and lead to invalid configuration with undefined behavior. This issue affects: Gallagher Command Centre 8.90 prior to vEL8.90.1620 (MR2), all versions of 8.80 and prior.

  • CVE-2023-20172MedMay 18, 2023
    risk 0.35cvss 5.4epss 0.00

    Multiple vulnerabilities in Cisco Identity Services Engine (ISE) could allow an authenticated attacker to delete or read arbitrary files on the underlying operating system. To exploit these vulnerabilities, an attacker must have valid credentials on an affected device. For more…

  • CVE-2023-20171MedMay 18, 2023
    risk 0.35cvss 5.4epss 0.00

    Multiple vulnerabilities in Cisco Identity Services Engine (ISE) could allow an authenticated attacker to delete or read arbitrary files on the underlying operating system. To exploit these vulnerabilities, an attacker must have valid credentials on an affected device. For more…

  • CVE-2023-20106MedMay 18, 2023
    risk 0.35cvss 5.4epss 0.00

    Multiple vulnerabilities in Cisco Identity Services Engine (ISE) could allow an authenticated attacker to delete or read arbitrary files on the underlying operating system. To exploit these vulnerabilities, an attacker must have valid credentials on an affected device. For more…

  • CVE-2023-0581MedJan 30, 2023
    risk 0.35cvss 5.3epss 0.01

    The PrivateContent plugin for WordPress is vulnerable to protection mechanism bypass due to the use of client side validation in versions up to, and including, 8.4.3. This is due to the plugin checking if an IP had been blocklist via client-side scripts rather than server-side.…

  • CVE-2026-14831MedAug 6, 2026
    risk 0.34cvss 5.3epss 0.00

    The Easy Booking WordPress plugin before 3.5.0 does not re-enforce a bookable product's configured minimum booking duration on the server side when adding to cart and calculating the booking price, allowing unauthenticated users to place below-minimum bookings and complete…

  • CVE-2026-0808MedJan 17, 2026
    risk 0.34cvss 5.3epss 0.00

    The Spin Wheel plugin for WordPress is vulnerable to client-side prize manipulation in all versions up to, and including, 2.1.0. This is due to the plugin trusting client-supplied prize selection data without server-side validation or randomization. This makes it possible for…

  • CVE-2025-54833MedJul 31, 2025
    risk 0.34cvss 5.3epss 0.01

    OPEXUS FOIAXpress Public Access Link (PAL) version v11.1.0 allows attackers to bypass account-lockout and CAPTCHA protections. Unauthenticated remote attackers can more easily brute force passwords.

  • CVE-2025-27367MedJul 8, 2025
    risk 0.34cvss 5.3epss 0.00

    IBM OpenPages with Watson 8.3 and 9.0 is vulnerable to improper input validation due to bypassing of client-side validation for the data types and requiredness of fields for GRC Objects when an authenticated user sends a specially crafted payload to the server allowing for…

  • CVE-2025-43699MedJun 10, 2025
    risk 0.34cvss 5.3epss 0.00

    Client-Side Enforcement of Server-Side Security vulnerability in Salesforce OmniStudio (FlexCards) allows bypass of required permission check.  This impacts OmniStudio: before Spring 2025

  • CVE-2024-32685MedMay 17, 2024
    risk 0.34cvss 5.3epss 0.00

    Client-Side Enforcement of Server-Side Security vulnerability in Wpmet Wp Ultimate Review allows Functionality Bypass.This issue affects Wp Ultimate Review: from n/a through 2.2.5.

  • CVE-2024-32521MedMay 17, 2024
    risk 0.34cvss 5.3epss 0.00

    Client-Side Enforcement of Server-Side Security vulnerability in Highfivery LLC Zero Spam allows Removing Important Client Functionality.This issue affects Zero Spam: from n/a through 5.5.6.

  • CVE-2024-32512MedMay 17, 2024
    risk 0.34cvss 5.3epss 0.00

    Client-Side Enforcement of Server-Side Security vulnerability in weForms allows Removing Important Client Functionality.This issue affects weForms: from n/a through 1.6.20.