Weaknesses of type CWE-640

219 results

Mecanismo fraco de recuperação de senha

É quando o sistema oferece um fluxo para recuperar senhas perdidas, mas esse fluxo usa verificações insuficientes (perguntas fáceis de responder, tokens previsíveis, links sem expiração) ou permite múltiplas tentativas sem limite. Um atacante consegue contornar a autenticação e assumir a conta sem saber a senha original.

Example

Um site que envia um e-mail com link de reset contendo um ID sequencial (user_id=1001, user_id=1002...), sem expiração, ou que valida a recuperação apenas pedindo a 'data de nascimento' — dados frequentemente públicos em redes sociais.

How to mitigate

Use tokens criptograficamente seguros e aleatórios com expiração curta (15-30 min). Implemente rate limiting rigoroso no fluxo de recuperação, valide o link apenas uma vez e considere autenticação multi-fator (SMS, app authenticator) como segunda camada de confirmação.

CVE-2024-48428CRITICALAn issue in Olive VLE allows an attacker to obtain sensitive information via the reset password function.EPSS 0.8%CVE-2022-26872HIGHPassword reset interception via APIEPSS 0.8%CVE-2022-50910HIGHBeehive Forum - Account TakeoverEPSS 0.8%CVE-2022-37300CRITICALA CWE-640: Weak Password Recovery Mechanism for Forgotten Password vulnerability exists that could cause unauthorized access in read and wriEPSS 0.8%CVE-2024-33530HIGHIn Jitsi Meet before 9391, a logic flaw in password-protected Jitsi meetings (that make use of a lobby) leads to the disclosure of the meetiEPSS 0.8%CVE-2024-0425MEDIUMForU CMS password recoveryEPSS 0.7%CVE-2026-37106CRITICALAn issue in DokuWiki 2025-05-14b "Librarian" 56.2 allows a remote attacker to create an account via the register function in inc/auth.php. NEPSS 0.7%CVE-2023-28821MEDIUMConcrete CMS (previously concrete5) before 9.1 did not have a rate limit for password resets.EPSS 0.7%CVE-2026-7652MEDIUMLatePoint <= 5.5.0 - Unauthenticated Account Takeover via Weak Password Recovery MechanismEPSS 0.7%CVE-2025-6097MEDIUMUTT 进取 750W Administrator Password setSysAdm formDefineManagement unverified password changeEPSS 0.7%CVE-2020-37172HIGHAVideo Platform 8.1 - Cross Site Request Forgery (Password Reset)EPSS 0.7%CVE-2024-11350CRITICALAdForest <= 5.1.6 - Privilege Escalation via Password Reset/Account TakeoverEPSS 0.7%CVE-2024-9305HIGHAppPresser – Mobile App Framework <= 4.4.4 - Privilege Escalation and Account Takeover via Weak OTPEPSS 0.7%CVE-2023-3222HIGHVulnerability in the password recovery mechanism of Roundcube Password Recovery PluginEPSS 0.7%CVE-2023-5840MEDIUMWeak Password Recovery Mechanism for Forgotten Password in linkstackorg/linkstackEPSS 0.7%CVE-2026-12416CRITICALInvoice Generator <= 1.0.0 - Unauthenticated Account Takeover via Weak Password Reset Validation via 'reset_user_id' ParameterEPSS 0.7%CVE-2026-28268CRITICALVikunja Vulnerable to Account Takeover via Password Reset Token ReuseEPSS 0.7%CVE-2024-47547CRITICALRuijie Reyee OS Weak Password Recovery Mechanism for Forgotten PasswordEPSS 0.7%CVE-2026-15155HIGHEssential Addons for Elementor <= 6.6.10 - Authenticated (Contributor+) Account Takeover via Email Header InjectionEPSS 0.7%CVE-2026-55207HIGHPimcore: Account Takeover via Password Reset URL Injection allows unauthenticated attacker to hijack any admin account with 2FA bypassEPSS 0.7%