We have a JSP page with a form, and assuming that just before submitting the form, the request is intercepted and the values entered by authorized user is tampered by some h