VYPR

CWE-640

Weak Password Recovery Mechanism for Forgotten Password

BaseIncompleteLikelihood: High

Description

The product contains a mechanism for users to recover or change their passwords without knowing the original password, but the mechanism is weak.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-50

CVEs mapped to this weakness (328)

page 6 of 17
  • CVE-2023-49589HigJan 10, 2024
    risk 0.57cvss 8.8epss 0.01

    An insufficient entropy vulnerability exists in the userRecoverPass.php recoverPass generation functionality of WWBN AVideo dev master commit 15fed957fb. A specially crafted HTTP request can lead to an arbitrary user password recovery. An attacker can send an HTTP request to…

  • CVE-2023-47107HigNov 8, 2023
    risk 0.57cvss 8.8epss 0.01

    PILOS is an open source front-end for BigBlueButton servers with a built-in load balancer. The password reset component deployed within PILOS uses the hostname supplied within the request host header when building a password reset URL. It may be possible to manipulate the URL…

  • CVE-2023-31459HigMay 24, 2023
    risk 0.57cvss 8.8epss 0.00

    A vulnerability in the Connect Mobility Router component of Mitel MiVoice Connect versions 9.6.2208.101 and earlier could allow an unauthenticated attacker with internal network access to authenticate with administrative privileges, because the initial installation does not…

  • CVE-2021-31912HigMay 11, 2021
    risk 0.57cvss 8.8epss 0.01

    In JetBrains TeamCity before 2020.2.3, account takeover was potentially possible during a password reset.

  • CVE-2020-25728HigSep 17, 2020
    risk 0.57cvss 8.8epss 0.01

    The Reset Password add-on before 1.2.0 for Alfresco has a broken algorithm (involving an increment) that allows a malicious user to change any user's account password include the admin account.

  • CVE-2017-18908CriJun 19, 2020
    risk 0.57cvss 9.8epss 0.01

    An issue was discovered in Mattermost Server before 4.0.0, 3.10.2, and 3.9.2. A password-reset request was sometime sent to an attacker-provided e-mail address.

  • CVE-2012-5618CriFeb 4, 2020
    risk 0.57cvss 9.8epss 0.01

    Ushahidi before 2.6.1 has insufficient entropy for forgot-password tokens.

  • CVE-2019-20004HigJan 5, 2020
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered on Intelbras IWR 3000N 1.8.7 devices. When the administrator password is changed from a certain client IP address, administrative authorization remains available to any client at that IP address, leading to complete control of the router.

  • CVE-2019-10270HigJun 21, 2019
    risk 0.57cvss 8.8epss 0.01

    An arbitrary password reset issue was discovered in the Ultimate Member plugin 2.39 for WordPress. It is possible (due to lack of verification and correlation between the reset password key sent by mail and the user_id parameter) to reset the password of another user. One only…

  • CVE-2019-11414HigApr 22, 2019
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered on Intelbras IWR 3000N 1.5.0 devices. When the administrator password is changed from a certain client IP address, administrative authorization remains available to any client at that IP address, leading to complete control of the router.

  • CVE-2019-10641CriApr 17, 2019
    risk 0.57cvss 9.8epss 0.01

    Contao before 3.5.39 and 4.x before 4.7.3 has a Weak Password Recovery Mechanism for a Forgotten Password.

  • CVE-2018-17401HigSep 23, 2018
    risk 0.57cvss 8.8epss 0.01

    The PhonePe wallet (aka com.PhonePe.app) application 3.0.6 through 3.3.26 for Android might allow attackers to perform Account Takeover attacks by exploiting its Forgot Password feature. NOTE: the vendor says that, to exploit this, the user has to explicitly install a malicious…

  • CVE-2018-11134HigMay 31, 2018
    risk 0.57cvss 8.8epss 0.03

    In order to perform actions that requires higher privileges, the Quest KACE System Management Appliance 8.0.318 relies on a message queue managed that runs with root privileges and only allows a set of commands. One of the available commands allows changing any user's password…

  • CVE-2015-5172CriOct 24, 2017
    risk 0.57cvss 9.8epss 0.01

    Cloud Foundry Runtime cf-release before 216, UAA before 2.5.2, and Pivotal Cloud Foundry (PCF) Elastic Runtime before 1.7.0 allow attackers to have unspecified impact by leveraging failure to expire password reset links.

  • CVE-2017-14005HigOct 17, 2017
    risk 0.57cvss 8.8epss 0.01

    An Unverified Password Change issue was discovered in ProMinent MultiFLEX M10a Controller web interface. When setting a new password for a user, the application does not require the user to know the original password. An attacker who is authenticated could change a user's…

  • CVE-2017-12851HigAug 14, 2017
    risk 0.57cvss 8.8epss 0.01

    An authenticated standard user could reset the password of the admin by altering form data. Affects kanboard before 1.0.46.

  • CVE-2017-12850HigAug 14, 2017
    risk 0.57cvss 8.8epss 0.01

    An authenticated standard user could reset the password of other users (including the admin) by altering form data. Affects kanboard before 1.0.46.

  • CVE-2023-4096HigSep 19, 2023
    risk 0.56cvss 8.6epss 0.00

    Weak password recovery mechanism vulnerability in Fujitsu Arconte Áurea version 1.5.0.0, which exploitation could allow an attacker to perform a brute force attack on the emailed PIN number in order to change the password of a legitimate user.

  • CVE-2026-33707CriApr 10, 2026
    risk 0.54cvss 9.4epss 0.00

    Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, the default password reset mechanism generates tokens using sha1($email) with no random component, no expiration, and no rate limiting. An attacker who knows a user's email can compute the reset token…

  • CVE-2025-29995HigMar 13, 2025
    risk 0.54cvss —epss 0.00

    This vulnerability exists in the CAP back office application due to a weak password-reset mechanism implemented at API endpoints. An authenticated remote attacker with a valid login ID could exploit this vulnerability through vulnerable API endpoint which could lead to account…