VYPR

CWE-620

Unverified Password Change

BaseDraft

Description

When setting a new password for a user, the product does not require knowledge of the original password, or using another form of authentication.

This could be used by an attacker to change passwords for another user, thus gaining the privileges associated with that user.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (92)

page 2 of 5
  • CVE-2023-2297CriApr 27, 2023
    risk 0.64cvss 9.8epss 0.01

    The Profile Builder – User Profile & User Registration Forms plugin for WordPress is vulnerable to unauthorized password resets in versions up to, and including 3.9.0. This is due to the plugin using native password reset functionality, with insufficient validation on the…

  • CVE-2026-5386CriMay 29, 2026
    risk 0.59cvss 9.1epss 0.01

    The affected KMW CCTV Security Cameras are vulnerable to a critical unauthenticated password reset. This flaw allows an attacker to remotely reset the administrator password to a known value without authentication, granting full access to the camera feeds and settings.

  • CVE-2026-30458CriMar 26, 2026
    risk 0.59cvss 9.1epss 0.00

    An issue in Daylight Studio FuelCMS v1.5.2 allows attackers to exfiltrate users' password reset tokens via a mail splitting attack.

  • CVE-2020-7378CriNov 24, 2020
    risk 0.59cvss 9.1epss 0.03

    CRIXP OpenCRX version 4.30 and 5.0-20200717 and prior suffers from an unverified password change vulnerability. An attacker who is able to connect to the affected OpenCRX instance can change the password of any user, including admin-Standard, to any chosen value. This issue was…

  • CVE-2026-24443HigFeb 24, 2026
    risk 0.57cvss 8.8epss 0.00

    EventSentry versions prior to 6.0.1.20 contain an unverified password change vulnerability in the account management functionality of the Web Reports interface. The password change mechanism does not require validation of the current password before allowing a new password to…

  • CVE-2026-24440HigJan 26, 2026
    risk 0.57cvss 8.8epss 0.00

    Shenzhen Tenda W30E V2 firmware versions up to and including V16.01.0.19(5037) allow account passwords to be changed through the maintenance interface without requiring verification of the existing password. This enables unauthorized password changes when access to the affected…

  • CVE-2025-14751HigJan 22, 2026
    risk 0.57cvss epss 0.00

    A low-privileged user can bypass account credentials without confirming the user's current authentication state, which may lead to unauthorized privilege escalation.

  • CVE-2025-9286CriOct 3, 2025
    risk 0.57cvss 9.8epss 0.00

    The Appy Pie Connect for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation due to missing authorization within the reset_user_password() REST handler in all versions up to, and including, 1.1.2. This makes it possible for unauthenticated attackers to to…

  • CVE-2025-5482HigJun 4, 2025
    risk 0.57cvss 8.8epss 0.01

    The Sunshine Photo Cart: Free Client Photo Galleries for Photographers plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 3.4.11. This is due to the plugin not properly validating a user-supplied key. This makes…

  • CVE-2025-3603CriApr 24, 2025
    risk 0.57cvss 9.8epss 0.01

    The Flynax Bridge plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 2.2.0. This is due to the plugin not properly validating a user's identity prior to updating their details like password. This makes it…

  • CVE-2024-9431HigMar 20, 2025
    risk 0.57cvss 8.8epss 0.01

    In version v0.0.14 of transformeroptimus/superagi, there is an improper privilege management vulnerability. After logging into the system, users can change the passwords of other users, leading to potential account takeover.

  • CVE-2017-14005HigOct 17, 2017
    risk 0.57cvss 8.8epss 0.01

    An Unverified Password Change issue was discovered in ProMinent MultiFLEX M10a Controller web interface. When setting a new password for a user, the application does not require the user to know the original password. An attacker who is authenticated could change a user's…

  • CVE-2024-28143HigDec 12, 2024
    risk 0.55cvss 8.4epss 0.00

    The password change function at /cgi/admin.cgi does not require the current/old password, which makes the application vulnerable to account takeover. An attacker can use this to forcefully set a new password within the -rsetpass+-aaction+- parameter for a user without knowing…

  • CVE-2025-62425HigOct 16, 2025
    risk 0.54cvss 8.3epss 0.00

    MAS (Matrix Authentication Service) is a user management and authentication service for Matrix homeservers, written and maintained by Element. A logic flaw in matrix-authentication-service 0.20.0 through 1.4.0 allows an attacker with access to an authenticated MAS session to…

  • CVE-2025-13148HigDec 11, 2025
    risk 0.53cvss 8.1epss 0.00

    IBM Aspera Orchestrator 4.0.0 through 4.1.0 could allow could an authenticated user to change the password of another user without prior knowledge of that password.

  • CVE-2025-61536HigOct 16, 2025
    risk 0.53cvss 8.2epss 0.00

    FelixRiddle dev-jobs-handlebars 1.0 uses absolute password-reset (magic) links using the untrusted `req.headers.host` header and forces the `http://` scheme. An attacker who can control the `Host` header (or exploit a misconfigured proxy/load-balancer that forwards the header…

  • CVE-2025-22381HigOct 16, 2025
    risk 0.53cvss 8.2epss 0.01

    Aggie 2.6.1 has a Host Header injection vulnerability in the forgot password functionality, allowing an attacker to reset a user's password.

  • CVE-2024-13373HigMar 1, 2025
    risk 0.53cvss 8.1epss 0.00

    The Exertio Framework plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.3.1. This is due to the plugin not properly validating a user's identity prior to updating their password through the…

  • CVE-2024-27715HigJul 5, 2024
    risk 0.53cvss 8.2epss 0.00

    An issue in Eskooly Free Online School management Software v.3.0 and before allows a remote attacker to escalate privileges via a crafted request to the Password Change mechanism.

  • CVE-2022-21934HigMay 6, 2022
    risk 0.52cvss 8.0epss 0.01

    Under certain circumstances an authenticated user could lock other users out of the system or take over their accounts in Metasys ADS/ADX/OAS server 10 versions prior to 10.1.5 and Metasys ADS/ADX/OAS server 11 versions prior to 11.0.2.