Weaknesses of type CWE-640

219 results

Mecanismo fraco de recuperação de senha

É quando o sistema oferece um fluxo para recuperar senhas perdidas, mas esse fluxo usa verificações insuficientes (perguntas fáceis de responder, tokens previsíveis, links sem expiração) ou permite múltiplas tentativas sem limite. Um atacante consegue contornar a autenticação e assumir a conta sem saber a senha original.

Example

Um site que envia um e-mail com link de reset contendo um ID sequencial (user_id=1001, user_id=1002...), sem expiração, ou que valida a recuperação apenas pedindo a 'data de nascimento' — dados frequentemente públicos em redes sociais.

How to mitigate

Use tokens criptograficamente seguros e aleatórios com expiração curta (15-30 min). Implemente rate limiting rigoroso no fluxo de recuperação, valide o link apenas uma vez e considere autenticação multi-fator (SMS, app authenticator) como segunda camada de confirmação.

CVE-2024-45980HIGHA host header injection vulnerability in MEANStore 1.0 allows attackers to obtain the password reset token via user interaction with a craftEPSS 0.4%CVE-2026-2895MEDIUMfunadmin Member.php repass password recoveryEPSS 0.4%CVE-2023-53958HIGHLDAP Tool Box Self Service Password 1.5.2 Account Takeover via HTTP Host HeaderEPSS 0.4%CVE-2024-9907MEDIUMQileCMS Verification Code Forget.php sendEmail password recoveryEPSS 0.4%CVE-2024-27899HIGHSecurity misconfiguration vulnerability in SAP NetWeaver AS Java User Management EngineEPSS 0.4%CVE-2025-62406HIGHPiwigo is vulnerable to one-click account takeover by modifying the password-reset linkEPSS 0.4%CVE-2026-71625CRITICALAn issue in slimkit plus ThinkSNS+ v.2.4 allows a remote attacker to escalate privileges via the ResetPasswordController.php componentEPSS 0.4%CVE-2025-69614CRITICALIncorrect Access Control via activation token reuse on the password-reset endpoint allowing unauthorized password resets and full account taEPSS 0.4%CVE-2024-6203HIGHHaloITSM - Password Reset PoisoningEPSS 0.4%CVE-2023-31459HIGHA vulnerability in the Connect Mobility Router component of Mitel MiVoice Connect versions 9.6.2208.101 and earlier could allow an unauthentEPSS 0.4%CVE-2020-5361MEDIUMSelect Dell Client Commercial and Consumer platforms support a BIOS password reset capability that is designed to assist authorized customerEPSS 0.4%CVE-2025-7948MEDIUMjshERP updatePwd password recoveryEPSS 0.4%CVE-2025-50594CRITICALAn issue was discovered in /Code/Websites/DanpheEMR/Controllers/Settings/SecuritySettingsController.cs in Danphe Health Hospital Management EPSS 0.4%CVE-2026-50635HIGHLimeSurvey Password Reset Host Header Injection Discloses Reset TokenEPSS 0.4%CVE-2025-8855HIGH2FA Expiry Bypass in Optimus Software's Brokerage AutomationEPSS 0.4%CVE-2024-50356NONEPress has a potential 2FA bypassEPSS 0.4%CVE-2025-3849MEDIUMYXJ2018 SpringBoot-Vue-OnlineExam studentPWD unverified password changeEPSS 0.4%CVE-2026-84699CRITICALTeam Password Manager before 14.184.308 Authentication Bypass in Password ResetEPSS 0.4%CVE-2024-24903HIGHDell Secure Connect Gateway (SCG) Policy Manager, version 5.10+, contain a weak password recovery mechanism for forgotten passwords. An adjaEPSS 0.4%CVE-2024-12295HIGHBoomBox Theme Extensions <= 1.8.0 - Authenticated (Subscriber+) Privilege Escalation via Password Reset/Account Takeover in boombox_ajax_reset_passwordEPSS 0.4%