Weaknesses of type CWE-640

219 results

Mecanismo fraco de recuperação de senha

É quando o sistema oferece um fluxo para recuperar senhas perdidas, mas esse fluxo usa verificações insuficientes (perguntas fáceis de responder, tokens previsíveis, links sem expiração) ou permite múltiplas tentativas sem limite. Um atacante consegue contornar a autenticação e assumir a conta sem saber a senha original.

Example

Um site que envia um e-mail com link de reset contendo um ID sequencial (user_id=1001, user_id=1002...), sem expiração, ou que valida a recuperação apenas pedindo a 'data de nascimento' — dados frequentemente públicos em redes sociais.

How to mitigate

Use tokens criptograficamente seguros e aleatórios com expiração curta (15-30 min). Implemente rate limiting rigoroso no fluxo de recuperação, valide o link apenas uma vez e considere autenticação multi-fator (SMS, app authenticator) como segunda camada de confirmação.

CVE-2025-13565MEDIUMSourceCodester Inventory Management System resetPassword.php password recoveryEPSS 0.5%CVE-2026-15479MEDIUMH3C NX15 Administrator Password Modification Endpoint modify change_passwd password recoveryEPSS 0.5%CVE-2023-35134HIGHWeintek Weincloud Weak Password Recovery Mechanism for Forgotten PasswordEPSS 0.5%CVE-2026-7655HIGHSureCart <= 4.2.3 - Unauthenticated Linked WordPress Account Takeover via Forged customer.updated WebhookEPSS 0.5%CVE-2026-27593CRITICALStatamic is vulnerable to account takeover via password reset link injectionEPSS 0.5%CVE-2024-6125HIGHLogin with phone number <= 1.7.34 - Insecure Password Reset MechanismEPSS 0.5%CVE-2026-28213CRITICALEverShop Vulnerable to Arbitrary Customer Account Takeover via Exposure of Password Reset Token in API ResponseEPSS 0.4%CVE-2025-1570HIGHDirectorist: AI-Powered Business Directory Plugin with Classified Ads Listings <= 8.1 - Privilege Escalation and Account Takeover via Weak OTPEPSS 0.4%CVE-2023-31287HIGHAn issue was discovered in Serenity Serene (and StartSharp) before 6.7.0. Password reset links are sent by email. A link contains a token thEPSS 0.4%CVE-2026-13019CRITICALMissing AuthenticationEPSS 0.4%CVE-2024-42915HIGHA host header injection vulnerability in Staff Appraisal System v1.0 allows attackers to obtain the password reset token via user interactioEPSS 0.4%CVE-2025-50433CRITICALAn issue was discovered in imonnit.com (2025-04-24) allowing malicious actors to gain escalated privileges via crafted password reset to takEPSS 0.4%CVE-2026-56308HIGHCapgo - Insufficient Authentication in Email Change EndpointEPSS 0.4%CVE-2026-86260MEDIUMsfturing hosp_order Password Recovery CommonUserController.java modifyPassWord unverified password changeEPSS 0.4%CVE-2026-28681HIGHIRRd: web UI host header injection allows password reset poisoning via attacker-controlled email linksEPSS 0.4%CVE-2026-33707CRITICALWeak Password Recovery Mechanism for Forgotten Password in chamilo/chamilo-lmsEPSS 0.4%CVE-2023-5296MEDIUMXinhu RockOA Password password recoveryEPSS 0.4%CVE-2024-38468CRITICALShenzhen Guoxin Synthesis image system before 8.3.0 allows unauthorized password resets via the resetPassword API.EPSS 0.4%CVE-2026-80196HIGHKimai before 2.58.0 Authentication Bypass via Password Reset LinkEPSS 0.4%CVE-2025-4319CRITICALImproper Access Control in Birebirsoft's SufirmamEPSS 0.4%