VYPR

CWE-620

Unverified Password Change

BaseDraft

Description

When setting a new password for a user, the product does not require knowledge of the original password, or using another form of authentication.

This could be used by an attacker to change passwords for another user, thus gaining the privileges associated with that user.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (92)

page 3 of 5
  • CVE-2025-3607HigApr 24, 2025
    risk 0.50cvss 8.8epss 0.00

    The Frontend Login and Registration Blocks plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.0.8. This is due to the plugin not properly validating a user's identity prior to updating a password. This makes it…

  • CVE-2022-21935HigJun 15, 2022
    risk 0.49cvss 7.5epss 0.01

    A vulnerability in Metasys ADS/ADX/OAS 10 versions prior to 10.1.5 and Metasys ADS/ADX/OAS 11 versions prior to 11.0.2 allows unverified password change.

  • CVE-2025-67719HigDec 11, 2025
    risk 0.48cvss epss 0.00

    Ibexa is a composable end-to-end DXP (Digital Experience Platform). Versions 5.0.0-beta1 through 5.0.3 do not have password validation. During the transition from v4 to v5 an error was introduced into validation code which causes the validation of the previous password not to…

  • CVE-2026-73292HigAug 12, 2026
    risk 0.47cvss 8.3epss 0.00

    Semaphore UI is a web interface for managing DevOps tools. Prior to 2.18.21, the /api/users/{id}/password endpoint accepts a cross-site request using the authenticated user's semaphore session cookie without CSRF protection or current-password confirmation, allowing an…

  • CVE-2026-54801HigJul 9, 2026
    risk 0.47cvss 7.2epss 0.00

    A vulnerability has been identified in CPCI85 Central Processing/Communication (All versions < V26.20), SICORE Base system (All versions < V26.20.0). The affected application contains insufficient validation of authentication credentials when processing administrative account…

  • CVE-2025-71328HigJun 25, 2026
    risk 0.47cvss 8.3epss 0.00

    Flowise before 3.0.10 contains an unverified password change vulnerability. An authenticated user can change their account password through the account settings (Security) section without supplying the current password or any additional verification, as the application does not…

  • CVE-2025-71337HigJun 23, 2026
    risk 0.47cvss 8.3epss 0.00

    Flowise before 3.0.10 (affected versions 3.0.7 and earlier) contains an unverified email change vulnerability. An authenticated user can change the account email address, used as a login identifier and password-recovery channel, via the account profile endpoint without…

  • CVE-2026-42084HigMay 4, 2026
    risk 0.46cvss 8.1epss 0.00

    OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to versions 6.10.5 and 7.0.0-rc3, the OpenC3 password change functionality allows a user to change their password without providing the old password, by…

  • CVE-2026-40588HigApr 21, 2026
    risk 0.46cvss 8.1epss 0.00

    blueprintUE is a tool to help Unreal Engine developers. Prior to 4.2.0, the password change form at /profile/{slug}/edit/ does not include a current_password field and does not verify the user's existing password before accepting a new one. Any attacker who obtains a valid…

  • CVE-2026-27757HigFeb 27, 2026
    risk 0.46cvss 7.1epss 0.00

    SODOLA SL902-SWTGW124AS firmware versions through 200.1.20 contain an authentication vulnerability that allows authenticated users to change account passwords without verifying the current password. Attackers who gain access to an authenticated session can modify credentials to…

  • CVE-2025-61132HigOct 23, 2025
    risk 0.46cvss 7.1epss 0.00

    A Host Header Injection vulnerability in the password reset component in levlaz braindump v0.4.14 allows remote attackers to conduct password reset poisoning and account takeover via manipulation of the Host header when Flask's url_for(_external=True) generates reset links…

  • CVE-2023-4214HigNov 18, 2023
    risk 0.46cvss 8.1epss 0.01

    The AppPresser plugin for WordPress is vulnerable to unauthorized password resets in versions up to, and including 4.2.5. This is due to the plugin generating too weak a reset code, and the code used to reset the password has no attempt or time limit.

  • CVE-2026-17599MedAug 7, 2026
    risk 0.45cvss epss 0.00

    Nexus Repository 3 contained an endpoint used to change the administrator account password during initial onboarding. This endpoint did not verify that onboarding was still in progress before allowing the password change, relying instead on the presence of a local onboarding…

  • CVE-2026-46623higJun 26, 2026
    risk 0.45cvss epss

    ## Summary **Description** An Unverified Password Change (CWE-620) and Use of Weak Credentials (CWE-1391) issue in OpenAM's OAuth2 authentication module silently rewrites a local user's password to the literal string of their username on OAuth2 re-login of an existing account.…

  • CVE-2025-59808MedDec 9, 2025
    risk 0.44cvss 6.8epss 0.00

    An unverified password change vulnerability [CWE-620] vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.2, FortiSOAR PaaS 7.5.0 through 7.5.1, FortiSOAR PaaS 7.4 all versions, FortiSOAR PaaS 7.3 all versions, FortiSOAR on-premise 7.6.0 through 7.6.2, FortiSOAR…

  • CVE-2022-2930HigAug 22, 2022
    risk 0.44cvss 7.8epss 0.00

    Unverified Password Change in GitHub repository octoprint/octoprint prior to 1.8.3.

  • CVE-2025-46389MedAug 6, 2025
    risk 0.42cvss 6.5epss 0.00

    CWE-620: Unverified Password Change

  • CVE-2024-41796MedApr 8, 2025
    risk 0.42cvss 6.5epss 0.00

    A vulnerability has been identified in SENTRON 7KT PAC1260 Data Manager (All versions). The web interface of affected devices allows to change the login password without knowing the current password. In combination with a prepared CSRF attack (CVE-2024-41795) an unauthenticated…

  • CVE-2023-25931MedMar 1, 2023
    risk 0.42cvss 6.4epss 0.00

    Medtronic identified that the Pelvic Health clinician apps, which are installed on the Smart Programmer mobile device, have a password vulnerability that requires a security update to fix. Not updating could potentially result in unauthorized control of the clinician therapy…

  • CVE-2021-34786MedSep 9, 2021
    risk 0.42cvss 6.5epss 0.01

    Multiple vulnerabilities in Cisco BroadWorks CommPilot Application Software could allow an authenticated, remote attacker to delete arbitrary user accounts or gain elevated privileges on an affected system.