The web application does not sufficiently verify inputs that are assumed to be immutable but are actually externally controllable, such as hidden form fields.