Weaknesses of type CWE-602

174 results

Confiança inadequada em mecanismo de proteção implementado no cliente

O servidor delega para o cliente (navegador, app, dispositivo) a responsabilidade de implementar uma proteção que deveria ser garantida no servidor. Isso é perigoso porque o cliente está sob controle do atacante — qualquer validação, restrição ou lógica de segurança implementada apenas no lado do cliente pode ser contornada, alterada ou removida. O servidor fica vulnerável quando assume que o cliente vai cumprir as regras.

Example

Um e-commerce que valida limite de quantidade de compra apenas no JavaScript do frontend, ou um banco que confere crédito disponível apenas no navegador antes de enviar a transação. Um atacante modifica o código do cliente, remove a validação ou faz requisições diretas ao servidor, contornando a proteção completamente.

How to mitigate

Implemente toda validação, autenticação e autorização críticas no servidor. Nunca confie em mecanismos de segurança executados apenas no cliente. Use validação no cliente para UX, mas sempre revalide e reforce as regras no backend antes de qualquer operação sensível.

CVE-2025-32808HIGHW. W. Norton InQuizitive through 2025-04-08 allows students to insert arbitrary records of their quiz performance into the backend, because EPSS 0.4%CVE-2025-1838MEDIUMIBM Cloud Pak for Business Automation denial of serviceEPSS 0.4%CVE-2025-53969HIGHCognex In-Sight Explorer and In-Sight Camera Firmware Client-Side Enforcement of Server-Side SecurityEPSS 0.4%CVE-2025-56694MEDIUMClient-side password validation (CWE-602) in lumasoft fotoShare Cloud 2025-03-13 allowing unauthenticated attackers to view password-protectEPSS 0.4%CVE-2024-32685MEDIUMWordPress WP Ultimate Review plugin <= 2.2.5 - Review Score Manipulation vulnerabilityEPSS 0.4%CVE-2023-20171MEDIUMCisco Identity Services Engine Arbitrary File Delete and File Read VulnerabilitiesEPSS 0.4%CVE-2026-30783MEDIUMRustDesk Client Can Orphan API Channel to Ignore All Admin Commands and ACL PoliciesEPSS 0.4%CVE-2023-30955MEDIUMFoundry workspace-server Developer Mode Authorization BypassEPSS 0.4%CVE-2023-20106MEDIUMCisco Identity Services Engine Arbitrary File Delete and File Read VulnerabilitiesEPSS 0.4%CVE-2026-84110MEDIUMReleasit Releasit COD Form & Upsells OTP Validation client-side enforcement of server-side securityEPSS 0.4%CVE-2026-63301HIGHDenial of Service in Quick.CMSEPSS 0.4%CVE-2025-36327MEDIUMVulnerabilities found in Watson Data IntelligenceEPSS 0.4%CVE-2021-36338MEDIUMUnisphere for PowerMax versions prior to 9.2.2.2 contains a privilege escalation vulnerability. An adjacent malicious user could potentiallyEPSS 0.4%CVE-2025-25497HIGHAn issue in account management interface in Netsweeper Server v.8.2.6 and earlier (fixed in v.8.2.7) allows unauthorized changes to the "AccEPSS 0.4%CVE-2026-0808MEDIUMSpin Wheel <= 2.1.0 - Unauthenticated Client-Side Prize Manipulation via 'prize_index' ParameterEPSS 0.4%CVE-2026-17756MEDIUMInsufficient policy enforcement in Presentation in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to bypass navigation restrEPSS 0.4%CVE-2024-20476MEDIUMCisco Identity Services Engine Authorization Bypass VulnerabilityEPSS 0.4%CVE-2024-32521MEDIUMWordPress Zero Spam for WordPress plugin <= 5.5.6 - Bypass Spam Protection vulnerabilityEPSS 0.4%CVE-2026-13919MEDIUMInsufficient policy enforcement in Extensions in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the rendEPSS 0.3%CVE-2026-13930MEDIUMInsufficient policy enforcement in Actor in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to bypass navigation restrictionsEPSS 0.3%