VYPR

CWE-640

Weak Password Recovery Mechanism for Forgotten Password

BaseIncompleteLikelihood: High

Description

The product contains a mechanism for users to recover or change their passwords without knowing the original password, but the mechanism is weak.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-50

CVEs mapped to this weakness (309)

page 9 of 16
  • CVE-2018-0696HigFeb 13, 2019
    risk 0.49cvss 7.5epss 0.01

    OpenAM (Open Source Edition) 13.0 and later does not properly manage sessions, which allows remote authenticated attackers to change the security questions and reset the login password via unspecified vectors.

  • CVE-2017-7629HigJun 15, 2017
    risk 0.49cvss 7.5epss 0.01

    QNAP QTS before 4.2.6 build 20170517 has a flaw in the change password function.

  • CVE-2017-9543HigJun 12, 2017
    risk 0.49cvss 7.5epss 0.01

    register.ghp in EFS Software Easy Chat Server versions 2.0 to 3.1 allows remote attackers to reset arbitrary passwords via a crafted POST request to registresult.htm.

  • CVE-2017-7731HigMay 27, 2017
    risk 0.49cvss 7.5epss 0.01

    A weak password recovery vulnerability in Fortinet FortiPortal versions 4.0.0 and below allows attacker to carry out information disclosure via the Forgotten Password feature.

  • CVE-2016-8716HigApr 12, 2017
    risk 0.49cvss 7.5epss 0.01

    An exploitable Cleartext Transmission of Password vulnerability exists in the Web Application functionality of Moxa AWK-3131A Wireless Access Point running firmware 1.1. The Change Password functionality of the Web Application transmits the password in cleartext. An attacker…

  • CVE-2016-2349HigDec 21, 2016
    risk 0.49cvss 7.5epss 0.01

    Remedy AR System Server in BMC Remedy 8.1 SP 2, 9.0, 9.0 SP 1, and 9.1 allows attackers to reset arbitrary passwords via a blank previous password.

  • CVE-2016-5996HigSep 26, 2016
    risk 0.49cvss 7.5epss 0.01

    The web portal in IBM Tealeaf Customer Experience before 8.7.1.8847 FP10, 8.8 before 8.8.0.9049 FP9, 9.0.0 and 9.0.1 before 9.0.1.1117 FP5, 9.0.1A before 9.0.1.5108_9.0.1A FP5, 9.0.2 before 9.0.2.1223 FP3, and 9.0.2A before 9.0.2.5224_9.0.2A FP3 does not enforce password-length…

  • CVE-2023-35134HigJul 19, 2023
    risk 0.48cvss 7.4epss 0.00

    Weintek Weincloud v0.13.6 could allow an attacker to reset a password with the corresponding account’s JWT token only.

  • CVE-2022-1073HigMar 29, 2022
    risk 0.48cvss 7.3epss 0.01

    A vulnerability was found in Automatic Question Paper Generator 1.0. It has been declared as critical. An attack leads to privilege escalation. The attack can be launched remotely.

  • CVE-2020-28186HigDec 24, 2020
    risk 0.48cvss 7.3epss 0.04

    Email Injection in TerraMaster TOS <= 4.2.06 allows remote unauthenticated attackers to abuse the forget password functionality and achieve account takeover.

  • CVE-2016-7038HigJan 20, 2017
    risk 0.48cvss 7.3epss 0.01

    In Moodle 2.x and 3.x, web service tokens are not invalidated when the user password is changed or forced to be changed.

  • CVE-2026-61049HigJul 21, 2026
    risk 0.46cvss 7.1epss 0.00

    Vulnerability in the Oracle Production Scheduling product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows unauthenticated attacker with access to the physical…

  • CVE-2026-35676HigMay 28, 2026
    risk 0.46cvss 8.2epss 0.00

    phpMyFAQ before 4.1.3 contains an unauthenticated password reset vulnerability in the user password update API endpoint that allows attackers to change account passwords without token validation. Attackers can enumerate valid username and email pairs and force immediate password…

  • CVE-2026-35675HigMay 28, 2026
    risk 0.46cvss 8.2epss 0.00

    phpMyFAQ before 4.1.3 contains an authentication bypass vulnerability in the password reset endpoint that allows unauthenticated attackers to reset any user account password without token verification or email confirmation. Attackers can enumerate valid usernames, obtain…

  • CVE-2026-42606HigMay 9, 2026
    risk 0.46cvss 8.1epss 0.00

    AzuraCast is a self-hosted, all-in-one web radio management suite. Prior to version 0.23.6, the ApplyXForwarded middleware unconditionally trusts the client-supplied X-Forwarded-Host HTTP header with no trusted proxy allowlist. An unauthenticated attacker can poison the password…

  • CVE-2026-29199HigMay 4, 2026
    risk 0.46cvss 8.1epss 0.00

    phpBB before 3.3.16 is vulnerable to Host Header Injection that can lead to password rest link poisoning. When force_server_vars is disabled, the servers hostname may be extracted from the HTTP Host header which is used to generate the password reset link URL. An attacker who…

  • CVE-2026-30459HigApr 16, 2026
    risk 0.46cvss 7.1epss 0.00

    An issue in the Forgot Password feature of Daylight Studio FuelCMS v1.5.2 allows unauthenticated attackers to obtain the password reset token of a victim user via a crafted link placed in a valid e-mail message.

  • CVE-2026-28681HigMar 6, 2026
    risk 0.46cvss 8.1epss 0.00

    Internet Routing Registry daemon version 4 is an IRR database server, processing IRR objects in the RPSL format. From version 4.4.0 to before version 4.4.5 and from version 4.5.0 to before version 4.5.1, an attacker can manipulate the HTTP Host header on a password reset or…

  • CVE-2025-64101HigOct 29, 2025
    risk 0.46cvss 8.1epss 0.00

    Zitadel is open-source identity infrastructure software. Prior to 4.6.0, 3.4.3, and 2.71.18, a potential vulnerability exists in ZITADEL's password reset mechanism. ZITADEL utilizes the Forwarded or X-Forwarded-Host header from incoming requests to construct the URL for the…

  • CVE-2025-61977HigOct 23, 2025
    risk 0.46cvss 7.0epss 0.00

    A weak password recovery mechanism for forgotten password vulnerability was discovered in Productivity Suite software version v4.4.1.19. The vulnerability allows an attacker to decrypt an encrypted project by answering just one recovery question.