Weaknesses of type CWE-620

100 results

Alteração de senha sem verificação

A aplicação permite que um usuário altere a senha de outro usuário (ou a sua própria) sem validar adequadamente a identidade ou solicitar a senha atual como comprovação. O atacante pode mudar credenciais sem autorização, tomando conta da conta ou bloqueando o proprietário legítimo.

Example

Um formulário de reset de senha que só pede o email, sem enviar token para confirmação, ou um endpoint de mudança de senha que não valida se o usuário autenticado é realmente o dono da conta sendo alterada. Um atacante consegue trocar a senha de qualquer usuário conhecendo apenas o ID ou email.

How to mitigate

Sempre exigir verificação de identidade antes de alterar senha: solicitar a senha atual, usar token de confirmação enviado por email/SMS, ou implementar autenticação multifator. Validar no backend que o usuário autenticado é o proprietário da conta cujos dados estão sendo modificados.

CVE-2024-45647MEDIUMIBM Security Verify Access unverified password changeEPSS 0.3%CVE-2024-28143HIGHInsecure Password Change FunctionEPSS 0.3%CVE-2023-25931MEDIUMMedtronic Micro Clinician & InterStim X Clinician App Password Reset IssueEPSS 0.3%CVE-2025-47938LOWTYPO3 Vulnerable to Unverified Password Change for Backend UsersEPSS 0.3%CVE-2026-27757HIGHSODOLA SL902-SWTGW124AS <= 200.1.20 Unverified Password ChangeEPSS 0.3%CVE-2025-46748LOWUnverified Password ChangeEPSS 0.3%CVE-2026-76633HIGHWeGIA < 3.9.2 Authorization Bypass Password Change via alterarSenhaEPSS 0.2%CVE-2024-2213LOWImproper Authentication in zenml-io/zenmlEPSS 0.2%CVE-2026-73292HIGHSemaphore UI: CSRF vulnerability on password change endpoint - No CSRF token or password confirmationEPSS 0.2%CVE-2025-59808MEDIUMAn unverified password change vulnerability [CWE-620] vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.2, FortiSOAR PaaS 7.5.0 thrEPSS 0.2%CVE-2025-46389MEDIUMCWE-620: Unverified Password ChangeEPSS 0.2%CVE-2025-3793MEDIUMBuddypress Force Password Change <= 0.1 - Authenticated (Subscriber+) Account Takeover via Password UpdateEPSS 0.2%CVE-2026-40588HIGHblueprintUE: Authenticated Password Change Does Not Verify Current PasswordEPSS 0.2%CVE-2025-11235LOWMOVEit Transfer REST API does not require current password in order to initiate the password change processEPSS 0.2%CVE-2019-25653MEDIUMNavicat for Oracle 12.1.15 Password Field Denial of ServiceEPSS 0.2%CVE-2024-21757MEDIUMA unverified password change in Fortinet FortiManager versions 7.0.0 through 7.0.10, versions 7.2.0 through 7.2.4, and versions 7.4.0 througEPSS 0.2%CVE-2024-47784LOWUnverified Password ChangeEPSS 0.2%CVE-2026-9249LOWUnverified password change in Devolutions Server allows an attacker to change a user's password without providing the previous one via a craEPSS 0.2%CVE-2026-8327MEDIUMConcrete CMS below 9.5.0 and below is vulnerable to password change without reauthorization and session-hardening bypass.EPSS 0.2%CVE-2025-67719HIGHIbexa User Bundle is missing password change validationEPSS 0.1%