VYPR

CWE-602

Client-Side Enforcement of Server-Side Security

ClassDraftLikelihood: Medium

Description

The product is composed of a server that relies on the client to implement a mechanism that is intended to protect the server.

When the server relies on protection mechanisms placed on the client side, an attacker can modify the client-side behavior to bypass the protection mechanisms, resulting in potentially unexpected interactions between the client and server. The consequences will vary, depending on what the mechanisms are trying to protect.

Hierarchy (View 1000)

Parents

Related attack patterns (CAPEC)

CAPEC-162 · CAPEC-202 · CAPEC-207 · CAPEC-208 · CAPEC-21 · CAPEC-31 · CAPEC-383 · CAPEC-384 · CAPEC-385 · CAPEC-386 · CAPEC-387 · CAPEC-388

CVEs mapped to this weakness (177)

page 9 of 9
  • CVE-2024-6620LowJul 29, 2024
    risk 0.23cvss 3.5epss 0.00

    Honeywell PC42t, PC42tp, and PC42d Printers, T10.19.020016 to T10.20.060398, contain a cross-site scripting vulnerability. A(n) attacker could potentially inject malicious code which may lead to information disclosure, session theft, or client-side request forgery. Honeywell…

  • CVE-2026-39415MedApr 8, 2026
    risk 0.21cvss 4.3epss 0.00

    Frappe Learning Management System (LMS) is a learning system that helps users structure their content. Prior to 2.46.0, a vulnerability has been identified in Frappe Learning where quiz scores can be modified by students before submission. The application currently relies on…

  • CVE-2025-36410LowJan 20, 2026
    risk 0.20cvss 3.1epss 0.00

    IBM ApplinX 11.1 could allow an authenticated user to perform unauthorized administrative actions on the server due to server-side enforcement of client-side security.

  • CVE-2026-23859LowFeb 24, 2026
    risk 0.18cvss 2.7epss 0.00

    Dell Wyse Management Suite, versions prior to WMS 5.5, contain a Client-Side Enforcement of Server-Side Security vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability to Protection mechanism bypass.

  • CVE-2025-36102LowDec 8, 2025
    risk 0.18cvss 2.7epss 0.00

    IBM Controller 11.1.0 through 11.1.1 and IBM Cognos Controller 11.0.0 through 11.0.1 FP6 could allow a privileged user to bypass validation, passing user input into the application as trusted data, due to client-side enforcement of server-side security.

  • CVE-2021-21544LowApr 30, 2021
    risk 0.18cvss 2.7epss 0.01

    Dell EMC iDRAC9 versions prior to 4.40.00.00 contain an improper authentication vulnerability. A remote authenticated malicious user with high privileges could potentially exploit this vulnerability to manipulate the username field under the comment section and set the value to…

  • CVE-2026-63301HigJul 28, 2026
    risk 0.00cvss —epss 0.00

    In Quick.CMS, the administrative user interface restricts deletion of the primary language by omitting the corresponding option from the interface; however, the underlying language-deletion API endpoint does not enforce an equivalent server-side authorization check. As a result,…

  • CVE-2026-64813CriJul 23, 2026
    risk 0.00cvss 10.0epss 0.01

    In JetBrains IntelliJ IDEA before 2026.2 unauthorized settings modification was possible in a Remote Development session

  • CVE-2026-65051MedJul 21, 2026
    risk 0.00cvss 6.5epss 0.00

    Ninja Forms WordPress plugin version 3.14.8 contains a client-side enforcement of server-side security vulnerability that allows unauthenticated attackers to bypass all form validation by merging attacker-controlled field metadata over server-loaded form definitions before…

  • CVE-2026-13724MedJul 20, 2026
    risk 0.00cvss 4.3epss 0.00

    Client-Side Enforcement of Server-Side Security vulnerability in Gobito Informatics Technologies Engineering Industry and Trade Ltd. Co. Corporate Training Management System allows Input Data Manipulation. This issue affects Corporate Training Management System: before…

  • CVE-2026-46485HigJul 15, 2026
    risk 0.00cvss 8.2epss 0.00

    Dashy is a self-hostable personal dashboard. Prior to 4.0.8, Dashy deployments using OIDC can allow unauthenticated users or non-admin authenticated users to write changes to the main config.yaml through the config-saving functionality despite configured permissions, allowing…

  • CVE-2025-36327MedJun 30, 2026
    risk 0.00cvss 6.5epss 0.00

    IBM watsonx.data intelligence 5.2.0, 5.2.1, 5.2.2, 5.3.0 could allow an authenticated user to bypass security controls and perform unauthorized actions due to client-side enforcement of sever-side security.

  • CVE-2026-57913HigJun 26, 2026
    risk 0.00cvss 7.5epss 0.00

    Johnson & Johnson Audit Tracking Management System (ATMS) before 2026-04-21 allows viewing of meeting minutes and transcripts.

  • CVE-2026-57912HigJun 26, 2026
    risk 0.00cvss 7.5epss 0.00

    Johnson & Johnson Campus Recruiting before 2025-10-31 allows viewing of data provided by recruited students, and notes entered about students by interviewers.

  • CVE-2017-12161HigFeb 21, 2018
    risk 0.00cvss 8.8epss 0.01

    It was found that keycloak before 3.4.2 final would permit misuse of a client-side /etc/hosts entry to spoof a URL in a password reset request. An attacker could use this flaw to craft a malicious password reset request and gain a valid reset token, leading to information…

  • CVE-2014-2374Nov 5, 2014
    risk 0.00cvss —epss 0.02

    The AXN-NET Ethernet module accessory 3.04 for the Accuenergy Acuvim II allows remote attackers to discover passwords and modify settings via vectors involving JavaScript.

  • CVE-2014-2373Nov 5, 2014
    risk 0.00cvss —epss 0.02

    The AXN-NET Ethernet module accessory 3.04 for the Accuenergy Acuvim II allows remote attackers to discover passwords and modify settings via vectors involving JavaScript.