VYPR

CWE-640

Weak Password Recovery Mechanism for Forgotten Password

BaseIncompleteLikelihood: High

Description

The product contains a mechanism for users to recover or change their passwords without knowing the original password, but the mechanism is weak.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-50

CVEs mapped to this weakness (328)

page 9 of 17
  • CVE-2024-5277HigJun 6, 2024
    risk 0.49cvss 7.5epss 0.00

    In lunary-ai/lunary version 1.2.4, a vulnerability exists in the password recovery mechanism where the reset password token is not invalidated after use. This allows an attacker who compromises the recovery token to repeatedly change the password of a victim's account. The issue…

  • CVE-2024-33530HigMay 2, 2024
    risk 0.49cvss 7.5epss 0.01

    In Jitsi Meet before 9391, a logic flaw in password-protected Jitsi meetings (that make use of a lobby) leads to the disclosure of the meeting password when a user is invited to a call after waiting in the lobby.

  • CVE-2023-3222HigSep 4, 2023
    risk 0.49cvss 7.5epss 0.01

    Vulnerability in the password recovery mechanism of Password Recovery plugin for Roundcube, in its 1.2 version, which could allow a remote attacker to change an existing user´s password by adding a 6-digit numeric token. An attacker could create an automatic script to test all…

  • CVE-2023-26615HigJun 28, 2023
    risk 0.49cvss 7.5epss 0.01

    D-Link DIR-823G firmware version 1.02B05 has a password reset vulnerability, which originates from the SetMultipleActions API, allowing unauthorized attackers to reset the WEB page management password.

  • CVE-2022-25027HigJan 12, 2023
    risk 0.49cvss 7.5epss 0.01

    The Forgotten Password functionality of Rocket TRUfusion Portal v7.9.2.1 allows remote attackers to bypass authentication and access restricted pages by validating the user's session token when the "Password forgotten?" button is clicked.

  • CVE-2020-12067HigDec 26, 2022
    risk 0.49cvss 7.5epss 0.01

    In Pilz PMC programming tool 3.x before 3.5.17 (based on CODESYS Development System), a user's password may be changed by an attacker without knowledge of the current password.

  • CVE-2021-43498HigApr 8, 2022
    risk 0.49cvss 7.5epss 0.02

    An Access Control vulnerability exists in ATutor 2.2.4 in password_reminder.php when the g, id, h, form_password_hidden, and form_change HTTP POST parameters are set.

  • CVE-2021-44037HigNov 19, 2021
    risk 0.49cvss 7.5epss 0.01

    Team Password Manager (aka TeamPasswordManager) before 10.135.236 allows password-reset poisoning.

  • CVE-2021-36708HigAug 6, 2021
    risk 0.49cvss 7.5epss 0.01

    In ProLink PRC2402M V1.0.18 and older, the set_sys_init function in the login.cgi binary allows an attacker to reset the password to the administrative interface of the router.

  • CVE-2021-30185HigApr 7, 2021
    risk 0.49cvss 7.5epss 0.01

    CERN Indico before 2.3.4 can use an attacker-supplied Host header in a password reset link.

  • CVE-2020-27408HigDec 4, 2020
    risk 0.49cvss 7.5epss 0.02

    OpenSIS Community Edition through 7.6 is affected by incorrect access controls for the file ResetUserInfo.php that allow an unauthenticated attacker to change the password of arbitrary users.

  • CVE-2020-14015HigJun 24, 2020
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in Navigate CMS 2.9 r1433. When performing a password reset, a user is emailed an activation code that allows them to reset their password. There is, however, a flaw when no activation code is supplied. The system will allow an unauthorized user to…

  • CVE-2009-5025HigJan 15, 2020
    risk 0.49cvss 7.5epss 0.02

    A backdoor (aka BMSA-2009-07) was found in PyForum v1.0.3 where an attacker who knows a valid user email could force a password reset on behalf of that user.

  • CVE-2018-0696HigFeb 13, 2019
    risk 0.49cvss 7.5epss 0.01

    OpenAM (Open Source Edition) 13.0 and later does not properly manage sessions, which allows remote authenticated attackers to change the security questions and reset the login password via unspecified vectors.

  • CVE-2017-7629HigJun 15, 2017
    risk 0.49cvss 7.5epss 0.01

    QNAP QTS before 4.2.6 build 20170517 has a flaw in the change password function.

  • CVE-2017-9543HigJun 12, 2017
    risk 0.49cvss 7.5epss 0.01

    register.ghp in EFS Software Easy Chat Server versions 2.0 to 3.1 allows remote attackers to reset arbitrary passwords via a crafted POST request to registresult.htm.

  • CVE-2017-7731HigMay 27, 2017
    risk 0.49cvss 7.5epss 0.01

    A weak password recovery vulnerability in Fortinet FortiPortal versions 4.0.0 and below allows attacker to carry out information disclosure via the Forgotten Password feature.

  • CVE-2016-8716HigApr 12, 2017
    risk 0.49cvss 7.5epss 0.01

    An exploitable Cleartext Transmission of Password vulnerability exists in the Web Application functionality of Moxa AWK-3131A Wireless Access Point running firmware 1.1. The Change Password functionality of the Web Application transmits the password in cleartext. An attacker…

  • CVE-2016-2349HigDec 21, 2016
    risk 0.49cvss 7.5epss 0.01

    Remedy AR System Server in BMC Remedy 8.1 SP 2, 9.0, 9.0 SP 1, and 9.1 allows attackers to reset arbitrary passwords via a blank previous password.

  • CVE-2016-5996HigSep 26, 2016
    risk 0.49cvss 7.5epss 0.01

    The web portal in IBM Tealeaf Customer Experience before 8.7.1.8847 FP10, 8.8 before 8.8.0.9049 FP9, 9.0.0 and 9.0.1 before 9.0.1.1117 FP5, 9.0.1A before 9.0.1.5108_9.0.1A FP5, 9.0.2 before 9.0.2.1223 FP3, and 9.0.2A before 9.0.2.5224_9.0.2A FP3 does not enforce password-length…