Weaknesses of type CWE-620

100 results

Alteração de senha sem verificação

A aplicação permite que um usuário altere a senha de outro usuário (ou a sua própria) sem validar adequadamente a identidade ou solicitar a senha atual como comprovação. O atacante pode mudar credenciais sem autorização, tomando conta da conta ou bloqueando o proprietário legítimo.

Example

Um formulário de reset de senha que só pede o email, sem enviar token para confirmação, ou um endpoint de mudança de senha que não valida se o usuário autenticado é realmente o dono da conta sendo alterada. Um atacante consegue trocar a senha de qualquer usuário conhecendo apenas o ID ou email.

How to mitigate

Sempre exigir verificação de identidade antes de alterar senha: solicitar a senha atual, usar token de confirmação enviado por email/SMS, ou implementar autenticação multifator. Validar no backend que o usuário autenticado é o proprietário da conta cujos dados estão sendo modificados.

CVE-2025-1107CRITICALUnverified password change vulnerability in JantoEPSS 0.4%CVE-2024-13373HIGHExertio Framework <= 1.3.1 - Unauthenticated Arbitrary User Password UpdateEPSS 0.4%CVE-2025-14751HIGHUnverified Password Change in Weintek cMT X Series HMI EasyWeb ServiceEPSS 0.4%CVE-2026-54175HIGHbackpack/crud: Unverified password change in MyAccountController via mass assignmentEPSS 0.4%CVE-2024-41796MEDIUMA vulnerability has been identified in SENTRON 7KT PAC1260 Data Manager (All versions). The web interface of affected devices allows to chanEPSS 0.4%CVE-2024-12827CRITICALDWT - Directory & Listing WordPress Theme <= 3.3.6 - Unauthenticated Arbitrary User Password ResetEPSS 0.4%CVE-2025-3849MEDIUMYXJ2018 SpringBoot-Vue-OnlineExam studentPWD unverified password changeEPSS 0.4%CVE-2026-30458CRITICALAn issue in Daylight Studio FuelCMS v1.5.2 allows attackers to exfiltrate users' password reset tokens via a mail splitting attack.EPSS 0.4%CVE-2024-27715HIGHAn issue in Eskooly Free Online School management Software v.3.0 and before allows a remote attacker to escalate privileges via a crafted reEPSS 0.4%CVE-2022-2930MEDIUMUnverified Password Change in octoprint/octoprintEPSS 0.3%CVE-2025-61132HIGHA Host Header Injection vulnerability in the password reset component in levlaz braindump v0.4.14 allows remote attackers to conduct passworEPSS 0.3%CVE-2026-77644CRITICALCritical Bypass Access Control Vulnerability Reported for Windchill Risk and Reliability (WRR) Enterprise EditionEPSS 0.3%CVE-2026-42084HIGHOpenC3 COSMOS: Hijacked session token can be used to reset password for persistenceEPSS 0.3%CVE-2026-85591HIGHphpMyFAQ before 4.1.8 Authentication Bypass via Unverified Password ChangeEPSS 0.3%CVE-2026-17599MEDIUMNexus Repository 3 - Unverified Onboarding State on change-admin-password EndpointEPSS 0.3%CVE-2026-2543MEDIUMvichan-devel vichan Password Change pages.php unverified password changeEPSS 0.3%CVE-2024-51493MEDIUMAPI key access in settings without reauthentication in OctoPrintEPSS 0.3%CVE-2026-24440HIGHTenda W30E V2 Allows Password Changes Without Verifying Current PasswordEPSS 0.3%CVE-2026-44733MEDIUMOpenProject: Business Logic Error on OpenProject through PATCH request to /api/v3/users/me permits to bypass password requirementsEPSS 0.3%CVE-2025-13148HIGHIBM Aspera Orchestrator Unverified Password ChangeEPSS 0.3%