Weaknesses of type CWE-640

219 results

Mecanismo fraco de recuperação de senha

É quando o sistema oferece um fluxo para recuperar senhas perdidas, mas esse fluxo usa verificações insuficientes (perguntas fáceis de responder, tokens previsíveis, links sem expiração) ou permite múltiplas tentativas sem limite. Um atacante consegue contornar a autenticação e assumir a conta sem saber a senha original.

Example

Um site que envia um e-mail com link de reset contendo um ID sequencial (user_id=1001, user_id=1002...), sem expiração, ou que valida a recuperação apenas pedindo a 'data de nascimento' — dados frequentemente públicos em redes sociais.

How to mitigate

Use tokens criptograficamente seguros e aleatórios com expiração curta (15-30 min). Implemente rate limiting rigoroso no fluxo de recuperação, valide o link apenas uma vez e considere autenticação multi-fator (SMS, app authenticator) como segunda camada de confirmação.

CVE-2025-14696MEDIUMShenzhen Sixun Software Sixun Shanghui Group Business Management System UpdatePasswordBatch password recoveryEPSS 0.3%CVE-2024-36407LOWSuiteCRM unauthenticated user password reset on php7EPSS 0.3%CVE-2026-66691CRITICALWordPress Nokri theme <= 1.6.6 - Broken Access Control vulnerabilityEPSS 0.3%CVE-2023-46138LOWJumpServer default admin user email leak password resetEPSS 0.3%CVE-2026-61143MEDIUMVulnerability in the Oracle Communications Convergent Charging Controller product of Oracle Communications (component: Prov IF). Supported EPSS 0.3%CVE-2026-53646HIGHFOSSBilling: Client password reset token reuse allows persistent account takeoverEPSS 0.3%CVE-2023-29145The Malwarebytes EDR 1.0.11 for Linux driver doesn't properly ensure whitelisting of executable libraries loaded by executable files, allowiEPSS 0.3%CVE-2026-93340HIGHGladys Assistant < 5.1.0 Password Reset Link Poisoning via forgot_password EndpointEPSS 0.3%CVE-2026-32865CRITICALOPEXUS eComplaint and eCase insecure password resetEPSS 0.3%CVE-2026-34751CRITICALPayload has Unvalidated Input in Password Recovery EndpointsEPSS 0.3%CVE-2024-43190MEDIUMIBM Engineering Requirements Management DOORS weak authenticationEPSS 0.3%CVE-2025-53373HIGHNatours has a 1 Click Account take over on reset password via Host Header injectionEPSS 0.3%CVE-2026-61049HIGHVulnerability in the Oracle Production Scheduling product of Oracle E-Business Suite (component: Internal Operations). Supported versions tEPSS 0.3%CVE-2026-18363CRITICALWeak password recovery mechanism in osTicket by Enhancesoft LLCEPSS 0.3%CVE-2026-14850HIGHWeak password recovery mechanism for forgotten password in MobiAPParcEPSS 0.3%CVE-2025-7881MEDIUMMercusys MW301R Web Interface password recoveryEPSS 0.3%CVE-2025-53704HIGHMAXHUB Pivot Weak Password Recovery Mechanism for Forgotten PasswordEPSS 0.3%CVE-2026-6285HIGHImproper Authentication in Ankaref's LIBRID/LIBREFEPSS 0.3%CVE-2025-63314CRITICALA static password reset token in the password reset function of DDSN Interactive Acora CMS v10.7.1 allows attackers to arbitrarily reset theEPSS 0.3%CVE-2026-12066MEDIUMPbootCMS Password MemberController.php retrieve password recoveryEPSS 0.3%