T 5.168 Bypassing security functions of web applications implemented on the client side

Web applications are usually accessed using generic clients (for example web browsers). Usually, these can be configured and adapted by the user. They are thus not subject to the control of the web application, but can be manipulated arbitrarily by an attacker who has obtained access. Thus, client-side security functions can be disabled. If no additional, server-side safeguards are planned, an attacker can thus access the resources of the web application.

Examples: