CWE-640
Weak Password Recovery Mechanism for Forgotten Password
Description
The product contains a mechanism for users to recover or change their passwords without knowing the original password, but the mechanism is weak.
Hierarchy (View 1000)
Parents
Children
none
Related attack patterns (CAPEC)
CAPEC-50
CVEs mapped to this weakness (309)
page 8 of 16| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-27654 | Hig | 0.51 | 7.8 | 0.01 | Jan 28, 2022 | Forgotten password reset functionality for local accounts can be used to bypass local authentication checks. | ||
| CVE-2017-8916 | Hig | 0.51 | 7.8 | 0.00 | Jan 31, 2018 | In Center for Internet Security CIS-CAT Pro Dashboard before 1.0.4, an authenticated user is able to change an administrative user's e-mail address and send a forgot password email to themselves, thereby gaining administrative access. | ||
| CVE-2026-50635 | Hig | 0.50 | 8.8 | 0.00 | Jun 9, 2026 | LimeSurvey constructs account password-reset links from the client-supplied HTTP Host header without validating it. The optional allowedHosts allowlist that would constrain this is undefined in the default (and documented) configuration, so LSHttpRequest::checkIsAllowedHost()… | ||
| CVE-2021-25957 | Hig | 0.50 | 8.8 | 0.01 | Aug 17, 2021 | In “Dolibarr” application, v2.8.1 to v13.0.2 are vulnerable to account takeover via password reset functionality. A low privileged attacker can reset the password of any user in the application using the password reset link the user received through email when requested for… | ||
| CVE-2026-61181 | Hig | 0.49 | 7.6 | 0.00 | Jul 21, 2026 | Vulnerability in the Oracle Agile Product Lifecycle Management for Process product of Oracle Supply Chain (component: Product Quality Management). The supported version that is affected is 6.2.4. Easily exploitable vulnerability allows low privileged attacker with network… | ||
| CVE-2023-53958 | Hig | 0.49 | 7.5 | 0.00 | Dec 19, 2025 | LDAP Tool Box Self Service Password 1.5.2 contains a password reset vulnerability that allows attackers to manipulate HTTP Host headers during token generation. Attackers can craft malicious password reset requests that generate tokens sent to a controlled server, enabling… | ||
| CVE-2025-53704 | Hig | 0.49 | 7.5 | 0.00 | Dec 4, 2025 | The password reset mechanism for the Pivot client application is weak, and it may allow an attacker to take over the account. | ||
| CVE-2024-5277 | Hig | 0.49 | 7.5 | 0.00 | Jun 6, 2024 | In lunary-ai/lunary version 1.2.4, a vulnerability exists in the password recovery mechanism where the reset password token is not invalidated after use. This allows an attacker who compromises the recovery token to repeatedly change the password of a victim's account. The issue… | ||
| CVE-2024-33530 | Hig | 0.49 | 7.5 | 0.01 | May 2, 2024 | In Jitsi Meet before 9391, a logic flaw in password-protected Jitsi meetings (that make use of a lobby) leads to the disclosure of the meeting password when a user is invited to a call after waiting in the lobby. | ||
| CVE-2023-3222 | Hig | 0.49 | 7.5 | 0.01 | Sep 4, 2023 | Vulnerability in the password recovery mechanism of Password Recovery plugin for Roundcube, in its 1.2 version, which could allow a remote attacker to change an existing user´s password by adding a 6-digit numeric token. An attacker could create an automatic script to test all… | ||
| CVE-2023-26615 | Hig | 0.49 | 7.5 | 0.01 | Jun 28, 2023 | D-Link DIR-823G firmware version 1.02B05 has a password reset vulnerability, which originates from the SetMultipleActions API, allowing unauthorized attackers to reset the WEB page management password. | ||
| CVE-2022-25027 | Hig | 0.49 | 7.5 | 0.01 | Jan 12, 2023 | The Forgotten Password functionality of Rocket TRUfusion Portal v7.9.2.1 allows remote attackers to bypass authentication and access restricted pages by validating the user's session token when the "Password forgotten?" button is clicked. | ||
| CVE-2020-12067 | Hig | 0.49 | 7.5 | 0.01 | Dec 26, 2022 | In Pilz PMC programming tool 3.x before 3.5.17 (based on CODESYS Development System), a user's password may be changed by an attacker without knowledge of the current password. | ||
| CVE-2021-43498 | Hig | 0.49 | 7.5 | 0.02 | Apr 8, 2022 | An Access Control vulnerability exists in ATutor 2.2.4 in password_reminder.php when the g, id, h, form_password_hidden, and form_change HTTP POST parameters are set. | ||
| CVE-2021-44037 | Hig | 0.49 | 7.5 | 0.01 | Nov 19, 2021 | Team Password Manager (aka TeamPasswordManager) before 10.135.236 allows password-reset poisoning. | ||
| CVE-2021-36708 | Hig | 0.49 | 7.5 | 0.01 | Aug 6, 2021 | In ProLink PRC2402M V1.0.18 and older, the set_sys_init function in the login.cgi binary allows an attacker to reset the password to the administrative interface of the router. | ||
| CVE-2021-30185 | Hig | 0.49 | 7.5 | 0.01 | Apr 7, 2021 | CERN Indico before 2.3.4 can use an attacker-supplied Host header in a password reset link. | ||
| CVE-2020-27408 | Hig | 0.49 | 7.5 | 0.02 | Dec 4, 2020 | OpenSIS Community Edition through 7.6 is affected by incorrect access controls for the file ResetUserInfo.php that allow an unauthenticated attacker to change the password of arbitrary users. | ||
| CVE-2020-14015 | Hig | 0.49 | 7.5 | 0.01 | Jun 24, 2020 | An issue was discovered in Navigate CMS 2.9 r1433. When performing a password reset, a user is emailed an activation code that allows them to reset their password. There is, however, a flaw when no activation code is supplied. The system will allow an unauthorized user to… | ||
| CVE-2009-5025 | Hig | 0.49 | 7.5 | 0.02 | Jan 15, 2020 | A backdoor (aka BMSA-2009-07) was found in PyForum v1.0.3 where an attacker who knows a valid user email could force a password reset on behalf of that user. |
- risk 0.51cvss 7.8epss 0.01
Forgotten password reset functionality for local accounts can be used to bypass local authentication checks.
- risk 0.51cvss 7.8epss 0.00
In Center for Internet Security CIS-CAT Pro Dashboard before 1.0.4, an authenticated user is able to change an administrative user's e-mail address and send a forgot password email to themselves, thereby gaining administrative access.
- risk 0.50cvss 8.8epss 0.00
LimeSurvey constructs account password-reset links from the client-supplied HTTP Host header without validating it. The optional allowedHosts allowlist that would constrain this is undefined in the default (and documented) configuration, so LSHttpRequest::checkIsAllowedHost()…
- risk 0.50cvss 8.8epss 0.01
In “Dolibarr” application, v2.8.1 to v13.0.2 are vulnerable to account takeover via password reset functionality. A low privileged attacker can reset the password of any user in the application using the password reset link the user received through email when requested for…
- risk 0.49cvss 7.6epss 0.00
Vulnerability in the Oracle Agile Product Lifecycle Management for Process product of Oracle Supply Chain (component: Product Quality Management). The supported version that is affected is 6.2.4. Easily exploitable vulnerability allows low privileged attacker with network…
- risk 0.49cvss 7.5epss 0.00
LDAP Tool Box Self Service Password 1.5.2 contains a password reset vulnerability that allows attackers to manipulate HTTP Host headers during token generation. Attackers can craft malicious password reset requests that generate tokens sent to a controlled server, enabling…
- risk 0.49cvss 7.5epss 0.00
The password reset mechanism for the Pivot client application is weak, and it may allow an attacker to take over the account.
- risk 0.49cvss 7.5epss 0.00
In lunary-ai/lunary version 1.2.4, a vulnerability exists in the password recovery mechanism where the reset password token is not invalidated after use. This allows an attacker who compromises the recovery token to repeatedly change the password of a victim's account. The issue…
- risk 0.49cvss 7.5epss 0.01
In Jitsi Meet before 9391, a logic flaw in password-protected Jitsi meetings (that make use of a lobby) leads to the disclosure of the meeting password when a user is invited to a call after waiting in the lobby.
- risk 0.49cvss 7.5epss 0.01
Vulnerability in the password recovery mechanism of Password Recovery plugin for Roundcube, in its 1.2 version, which could allow a remote attacker to change an existing user´s password by adding a 6-digit numeric token. An attacker could create an automatic script to test all…
- risk 0.49cvss 7.5epss 0.01
D-Link DIR-823G firmware version 1.02B05 has a password reset vulnerability, which originates from the SetMultipleActions API, allowing unauthorized attackers to reset the WEB page management password.
- risk 0.49cvss 7.5epss 0.01
The Forgotten Password functionality of Rocket TRUfusion Portal v7.9.2.1 allows remote attackers to bypass authentication and access restricted pages by validating the user's session token when the "Password forgotten?" button is clicked.
- risk 0.49cvss 7.5epss 0.01
In Pilz PMC programming tool 3.x before 3.5.17 (based on CODESYS Development System), a user's password may be changed by an attacker without knowledge of the current password.
- risk 0.49cvss 7.5epss 0.02
An Access Control vulnerability exists in ATutor 2.2.4 in password_reminder.php when the g, id, h, form_password_hidden, and form_change HTTP POST parameters are set.
- risk 0.49cvss 7.5epss 0.01
Team Password Manager (aka TeamPasswordManager) before 10.135.236 allows password-reset poisoning.
- risk 0.49cvss 7.5epss 0.01
In ProLink PRC2402M V1.0.18 and older, the set_sys_init function in the login.cgi binary allows an attacker to reset the password to the administrative interface of the router.
- risk 0.49cvss 7.5epss 0.01
CERN Indico before 2.3.4 can use an attacker-supplied Host header in a password reset link.
- risk 0.49cvss 7.5epss 0.02
OpenSIS Community Edition through 7.6 is affected by incorrect access controls for the file ResetUserInfo.php that allow an unauthenticated attacker to change the password of arbitrary users.
- risk 0.49cvss 7.5epss 0.01
An issue was discovered in Navigate CMS 2.9 r1433. When performing a password reset, a user is emailed an activation code that allows them to reset their password. There is, however, a flaw when no activation code is supplied. The system will allow an unauthorized user to…
- risk 0.49cvss 7.5epss 0.02
A backdoor (aka BMSA-2009-07) was found in PyForum v1.0.3 where an attacker who knows a valid user email could force a password reset on behalf of that user.