Fallos del tipo CWE-620

100 resultados

Mudança de Senha Sem Verificação

A aplicação permite que um usuário altere a senha de outro usuário ou a própria senha sem validar adequadamente a identidade de quem está fazendo a requisição. O atacante pode mudar senhas sem fornecer a senha atual, token de verificação ou qualquer outro fator de autenticação, comprometendo contas de outros usuários.

Ejemplo

Um formulário de 'Esqueci minha senha' aceita apenas o email e envia um link de reset que não expira ou pode ser adivinhado. Ou uma API de mudança de senha que não valida se o usuário autenticado é realmente o dono da conta sendo modificada (verifica apenas o ID da sessão, sem validar o param do user ID).

Cómo mitigar

Sempre exija autenticação forte antes de qualquer mudança de senha: peça a senha atual, implemente tokens de reset com expiração curta e associados à sessão, valide que o usuário autenticado é realmente o proprietário da conta sendo alterada, e registre o evento em log de auditoria.

CVE-2024-45647MEDIUMIBM Security Verify Access unverified password changeEPSS 0.3%CVE-2024-28143HIGHInsecure Password Change FunctionEPSS 0.3%CVE-2023-25931MEDIUMMedtronic Micro Clinician & InterStim X Clinician App Password Reset IssueEPSS 0.3%CVE-2025-47938LOWTYPO3 Vulnerable to Unverified Password Change for Backend UsersEPSS 0.3%CVE-2026-27757HIGHSODOLA SL902-SWTGW124AS <= 200.1.20 Unverified Password ChangeEPSS 0.3%CVE-2025-46748LOWUnverified Password ChangeEPSS 0.3%CVE-2026-76633HIGHWeGIA < 3.9.2 Authorization Bypass Password Change via alterarSenhaEPSS 0.2%CVE-2024-2213LOWImproper Authentication in zenml-io/zenmlEPSS 0.2%CVE-2026-73292HIGHSemaphore UI: CSRF vulnerability on password change endpoint - No CSRF token or password confirmationEPSS 0.2%CVE-2025-59808MEDIUMAn unverified password change vulnerability [CWE-620] vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.2, FortiSOAR PaaS 7.5.0 thrEPSS 0.2%CVE-2025-46389MEDIUMCWE-620: Unverified Password ChangeEPSS 0.2%CVE-2025-3793MEDIUMBuddypress Force Password Change <= 0.1 - Authenticated (Subscriber+) Account Takeover via Password UpdateEPSS 0.2%CVE-2026-40588HIGHblueprintUE: Authenticated Password Change Does Not Verify Current PasswordEPSS 0.2%CVE-2025-11235LOWMOVEit Transfer REST API does not require current password in order to initiate the password change processEPSS 0.2%CVE-2019-25653MEDIUMNavicat for Oracle 12.1.15 Password Field Denial of ServiceEPSS 0.2%CVE-2024-21757MEDIUMA unverified password change in Fortinet FortiManager versions 7.0.0 through 7.0.10, versions 7.2.0 through 7.2.4, and versions 7.4.0 througEPSS 0.2%CVE-2024-47784LOWUnverified Password ChangeEPSS 0.2%CVE-2026-9249LOWUnverified password change in Devolutions Server allows an attacker to change a user's password without providing the previous one via a craEPSS 0.2%CVE-2026-8327MEDIUMConcrete CMS below 9.5.0 and below is vulnerable to password change without reauthorization and session-hardening bypass.EPSS 0.2%CVE-2025-67719HIGHIbexa User Bundle is missing password change validationEPSS 0.1%