Not validating user actions on the Server
(1m 07s)
In the WebApp Framework, you build your user interface by placing a number of Web Objects like forms, buttons, etcetera. The thing is that, hiding or disabling the object does not mean it's not actually there or inaccessible. With some simple DOM manipulation or console magic, a malicious user can display information he's not meant to see or perform actions he's not allowed to perform.