Weaknesses of type CWE-640

219 results

Mecanismo fraco de recuperação de senha

É quando o sistema oferece um fluxo para recuperar senhas perdidas, mas esse fluxo usa verificações insuficientes (perguntas fáceis de responder, tokens previsíveis, links sem expiração) ou permite múltiplas tentativas sem limite. Um atacante consegue contornar a autenticação e assumir a conta sem saber a senha original.

Example

Um site que envia um e-mail com link de reset contendo um ID sequencial (user_id=1001, user_id=1002...), sem expiração, ou que valida a recuperação apenas pedindo a 'data de nascimento' — dados frequentemente públicos em redes sociais.

How to mitigate

Use tokens criptograficamente seguros e aleatórios com expiração curta (15-30 min). Implemente rate limiting rigoroso no fluxo de recuperação, valide o link apenas uma vez e considere autenticação multi-fator (SMS, app authenticator) como segunda camada de confirmação.

CVE-2022-22691MEDIUMUmbraco Password Reset URL PoisonEPSS 1.0%CVE-2021-36804MEDIUMAkaunting Password Reset RelayEPSS 1.0%CVE-2021-25961HIGHSuiteCRM - Account Takeover in Password Reset FunctionalityEPSS 1.0%CVE-2023-49589HIGHAn insufficient entropy vulnerability exists in the userRecoverPass.php recoverPass generation functionality of WWBN AVideo dev master commiEPSS 0.9%CVE-2022-3485CRITICALWeak Password Recovery in ifm moneo applianceEPSS 0.9%CVE-2026-24467CRITICALOpenAEV's Improper Password Reset Token Management Leads to Unauthenticated Account Takeover and Platform CompromiseEPSS 0.9%CVE-2026-26273CRITICALKnown affected by Account Takeover via Password Reset Token LeakageEPSS 0.9%CVE-2023-5959MEDIUMByzoro Smart S85F Management Platform login.php password recoveryEPSS 0.9%CVE-2022-24892MEDIUMMultiple valid tokens for password reset in ShopwareEPSS 0.9%CVE-2021-37693MEDIUMRe-use of email tokens in DiscourseEPSS 0.8%CVE-2023-50172MEDIUMA recovery notification bypass vulnerability exists in the userRecoverPass.php captcha validation functionality of WWBN AVideo dev master coEPSS 0.8%CVE-2023-43902HIGHIncorrect access control in the Forgot Your Password function of eMudhra emSigner v2.8.7 allows unauthenticated attackers to access accountsEPSS 0.8%CVE-2026-12417CRITICALSignUp & SignIn <= 1.0.0 - Unauthenticated Privilege Escalation via Weak Password Reset Validation via 'reset_activation_code' Leading to Account TakeoverEPSS 0.8%CVE-2024-53552CRITICALCrushFTP 10 before 10.8.3 and 11 before 11.2.3 mishandles password reset, leading to account takeover.EPSS 0.8%CVE-2022-1073HIGHAutomatic Question Paper Generator password recoveryEPSS 0.8%CVE-2025-4903MEDIUMD-Link DI-7003GV2 webgl.asp sub_41F4F0 unverified password changeEPSS 0.8%CVE-2025-41251HIGHWeak password recovery vulnerabilityEPSS 0.8%CVE-2022-45637CRITICALAn insecure password reset issue discovered in MEGAFEIS, BOFEI DBD+ Application for IOS & Android v1.4.4 service via insecure expiry mechaniEPSS 0.8%CVE-2024-11103CRITICALContest Gallery <= 24.0.7 - Unauthenticated Arbitrary Password Reset to Privilege Escalation/Account TakeoverEPSS 0.8%CVE-2023-49097HIGHZITADEL vulnerable account takeover via malicious host header injectionEPSS 0.8%