Fallos del tipo CWE-620

100 resultados

Mudança de Senha Sem Verificação

A aplicação permite que um usuário altere a senha de outro usuário ou a própria senha sem validar adequadamente a identidade de quem está fazendo a requisição. O atacante pode mudar senhas sem fornecer a senha atual, token de verificação ou qualquer outro fator de autenticação, comprometendo contas de outros usuários.

Ejemplo

Um formulário de 'Esqueci minha senha' aceita apenas o email e envia um link de reset que não expira ou pode ser adivinhado. Ou uma API de mudança de senha que não valida se o usuário autenticado é realmente o dono da conta sendo modificada (verifica apenas o ID da sessão, sem validar o param do user ID).

Cómo mitigar

Sempre exija autenticação forte antes de qualquer mudança de senha: peça a senha atual, implemente tokens de reset com expiração curta e associados à sessão, valide que o usuário autenticado é realmente o proprietário da conta sendo alterada, e registre o evento em log de auditoria.

CVE-2025-1107CRITICALUnverified password change vulnerability in JantoEPSS 0.4%CVE-2024-13373HIGHExertio Framework <= 1.3.1 - Unauthenticated Arbitrary User Password UpdateEPSS 0.4%CVE-2025-14751HIGHUnverified Password Change in Weintek cMT X Series HMI EasyWeb ServiceEPSS 0.4%CVE-2026-54175HIGHbackpack/crud: Unverified password change in MyAccountController via mass assignmentEPSS 0.4%CVE-2024-41796MEDIUMA vulnerability has been identified in SENTRON 7KT PAC1260 Data Manager (All versions). The web interface of affected devices allows to chanEPSS 0.4%CVE-2024-12827CRITICALDWT - Directory & Listing WordPress Theme <= 3.3.6 - Unauthenticated Arbitrary User Password ResetEPSS 0.4%CVE-2025-3849MEDIUMYXJ2018 SpringBoot-Vue-OnlineExam studentPWD unverified password changeEPSS 0.4%CVE-2024-27715HIGHAn issue in Eskooly Free Online School management Software v.3.0 and before allows a remote attacker to escalate privileges via a crafted reEPSS 0.4%CVE-2026-30458CRITICALAn issue in Daylight Studio FuelCMS v1.5.2 allows attackers to exfiltrate users' password reset tokens via a mail splitting attack.EPSS 0.4%CVE-2022-2930MEDIUMUnverified Password Change in octoprint/octoprintEPSS 0.3%CVE-2025-61132HIGHA Host Header Injection vulnerability in the password reset component in levlaz braindump v0.4.14 allows remote attackers to conduct passworEPSS 0.3%CVE-2026-77644CRITICALCritical Bypass Access Control Vulnerability Reported for Windchill Risk and Reliability (WRR) Enterprise EditionEPSS 0.3%CVE-2026-42084HIGHOpenC3 COSMOS: Hijacked session token can be used to reset password for persistenceEPSS 0.3%CVE-2026-85591HIGHphpMyFAQ before 4.1.8 Authentication Bypass via Unverified Password ChangeEPSS 0.3%CVE-2026-17599MEDIUMNexus Repository 3 - Unverified Onboarding State on change-admin-password EndpointEPSS 0.3%CVE-2026-2543MEDIUMvichan-devel vichan Password Change pages.php unverified password changeEPSS 0.3%CVE-2024-51493MEDIUMAPI key access in settings without reauthentication in OctoPrintEPSS 0.3%CVE-2026-24440HIGHTenda W30E V2 Allows Password Changes Without Verifying Current PasswordEPSS 0.3%CVE-2026-44733MEDIUMOpenProject: Business Logic Error on OpenProject through PATCH request to /api/v3/users/me permits to bypass password requirementsEPSS 0.3%CVE-2025-13148HIGHIBM Aspera Orchestrator Unverified Password ChangeEPSS 0.3%