VYPR

CWE-620

Unverified Password Change

BaseDraft

Description

When setting a new password for a user, the product does not require knowledge of the original password, or using another form of authentication.

This could be used by an attacker to change passwords for another user, thus gaining the privileges associated with that user.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (100)

page 5 of 5
  • CVE-2025-3849MedApr 22, 2025
    risk 0.28cvss 4.3epss 0.00

    A vulnerability classified as problematic was found in YXJ2018 SpringBoot-Vue-OnlineExam 1.0. This vulnerability affects unknown code of the file /api/studentPWD. The manipulation of the argument studentId leads to unverified password change. The attack can be initiated…

  • CVE-2025-3793MedApr 24, 2025
    risk 0.27cvss 4.2epss 0.00

    The Buddypress Force Password Change plugin for WordPress is vulnerable to authenticated account takeover due to the plugin not properly validating a user's identity prior to updating their password through the 'bp_force_password_ajax' function in all versions up to, and…

  • CVE-2024-51493MedNov 5, 2024
    risk 0.27cvss 5.3epss 0.00

    OctoPrint provides a web interface for controlling consumer 3D printers. OctoPrint versions up until and including 1.10.2 contain a vulnerability that allows an attacker that has gained temporary control over an authenticated victim's OctoPrint browser session to…

  • CVE-2025-11235LowJan 7, 2026
    risk 0.24cvss 3.7epss 0.00

    Unverified Password Change vulnerability in Progress MOVEit Transfer on Windows (REST API modules).This issue affects MOVEit Transfer: from 2023.1.0 before 2023.1.3, from 2023.0.0 before 2023.0.8, from 2022.1.0 before 2022.1.11, from 2022.0.0 before 2022.0.10.

  • CVE-2026-8327MedMay 21, 2026
    risk 0.21cvss 4.3epss 0.00

    Concrete CMS below 9.5.0 and below is vulnerable to password change without reauthorization and session-hardening bypass. The user-profile edit controller passes the entire raw POST array to UserInfo::update() without field whitelisting resulting in password change without…

  • CVE-2026-9249LowMay 22, 2026
    risk 0.20cvss 3.1epss 0.00

    Unverified password change in Devolutions Server allows an attacker to change a user's password without providing the previous one via a crafted password change request. This issue affects : * Devolutions Server 2026.1.6.0 through 2026.1.16.0 * Devolutions Server…

  • CVE-2024-23637MedJan 31, 2024
    risk 0.20cvss 4.2epss 0.01

    OctoPrint is a web interface for 3D printer.s OctoPrint versions up until and including 1.9.3 contain a vulnerability that allows malicious admins to change the password of other admin accounts, including their own, without having to repeat their password. An attacker who…

  • CVE-2025-70082LowMar 11, 2026
    risk 0.18cvss 2.7epss 0.00

    The administrator password can be changed without knowledge of the current password. When chained with an authentication bypass vulnerability, this issue may allow unauthenticated attackers to modify the administrator password.

  • CVE-2026-2543LowFeb 16, 2026
    risk 0.18cvss 2.7epss 0.00

    A vulnerability was identified in vichan-devel vichan up to 5.1.5. This vulnerability affects unknown code of the file inc/mod/pages.php of the component Password Change Handler. The manipulation of the argument Password leads to unverified password change. The attack can be…

  • CVE-2025-47938LowMay 20, 2025
    risk 0.18cvss 3.8epss 0.00

    TYPO3 is an open source, PHP based web content management system. Starting in version 9.0.0 and prior to versions 9.5.51 ELTS, 10.4.50 ELTS, 11.5.44 ELTS, 12.4.31 LTS, and 13.4.12 LTS, the backend user management interface allows password changes without requiring the current…

  • CVE-2025-46748LowMay 12, 2025
    risk 0.18cvss 2.7epss 0.00

    An authenticated user attempting to change their password could do so without using the current password.

  • CVE-2023-4465LowDec 29, 2023
    risk 0.18cvss 2.7epss 0.00

    A vulnerability, which was classified as problematic, was found in Poly Trio 8300, Trio 8500, Trio 8800, Trio C60, CCX 350, CCX 400, CCX 500, CCX 505, CCX 600, CCX 700, EDGE E100, EDGE E220, EDGE E300, EDGE E320, EDGE E350, EDGE E400, EDGE E450, EDGE E500, EDGE E550, VVX 101,…

  • CVE-2024-47784LowApr 30, 2025
    risk 0.17cvss 2.6epss 0.00

    Unverified Password Change for ANC software that allows an authenticated attacker to bypass the old Password check in the password change form via a web HMI This issue affects ANC software version 1.1.4 and earlier.

  • CVE-2024-2213LowJun 6, 2024
    risk 0.14cvss 3.3epss 0.00

    An issue was discovered in zenml-io/zenml versions up to and including 0.55.4. Due to improper authentication mechanisms, an attacker with access to an active user session can change the account password without needing to know the current password. This vulnerability allows for…

  • CVE-2026-12692CriJul 17, 2026
    risk 0.00cvss 9.8epss 0.01

    Unverified password change vulnerability in Vimesoft Inc. Enterprise Video Platform allows Authentication Bypass. This issue affects Enterprise Video Platform: from 3.11.0.0 before 3.25.0.

  • CVE-2026-56305HigJul 10, 2026
    risk 0.00cvss 8.3epss 0.01

    Capgo before 12.128.2 contains an authentication bypass vulnerability in the password change endpoint that allows attackers to change user passwords without requiring current password confirmation. Attackers with temporary session access can exploit this flaw to permanently lock…

  • CVE-2026-44733MedJun 26, 2026
    risk 0.00cvss 5.9epss 0.00

    OpenProject is open-source, web-based project management software. Prior to 17.3.2 and 17.4.0, Business Logic Error on OpenProject through PATCH request to /api/v3/users/me permits to bypass password requirements. A password validation flaw in the change password behavior allows…

  • CVE-2023-4381MedAug 16, 2023
    risk 0.00cvss 4.3epss 0.00

    Unverified Password Change in GitHub repository instantsoft/icms2 prior to 2.16.1-git.

  • CVE-2023-3069CriJun 2, 2023
    risk 0.00cvss 9.8epss 0.01

    Unverified Password Change in GitHub repository tsolucio/corebos prior to 8.

  • CVE-2022-3152HigSep 7, 2022
    risk 0.00cvss 8.8epss 0.01

    Unverified Password Change in GitHub repository phpfusion/phpfusion prior to 9.10.20.