Fallos del tipo CWE-640

219 resultados

Mecanismo fraco de recuperação de senha

A aplicação usa um processo de recuperação de senha insuficientemente seguro, permitindo que um atacante redefina a senha de outro usuário sem autenticação adequada. Isso acontece quando perguntas de segurança são previsíveis, tokens de recuperação não expiram, ou a validação de identidade é inadequada — abrindo caminho para takeover de conta.

Ejemplo

Um banco que envia um link de reset com token válido por 30 dias, ou um e-commerce que valida recuperação apenas perguntando a data de nascimento do cadastro (informação frequentemente pública). Um atacante consegue acessar contas alheias explorando essas fraquezas.

Cómo mitigar

Use tokens criptograficamente fortes e com expiração curta (15-60 min), exija confirmação em múltiplos canais (SMS + email), implemente rate limiting para tentativas de reset, e evite perguntas de segurança previsíveis ou públicas. Valide a identidade com dados realmente privados ou biometria quando possível.

CVE-2026-10169MEDIUMOUSL-GROUP-BrinaryBrains School Student Management System Forgot Password Endpoint Login.php ajax_forgot_password password recoveryEPSS 0.3%CVE-2026-14364CRITICALTrueBooker <= 1.2.3 - Missing Authorization to Unauthenticated Arbitrary Password Reset via 'tbab-userid'EPSS 0.3%CVE-2021-29038MEDIUMLiferay Portal 7.2.0 through 7.3.5, and older unsupported versions, and Liferay DXP 7.3 before fix pack 1, 7.2 before fix pack 17, and olderEPSS 0.3%CVE-2026-2543MEDIUMvichan-devel vichan Password Change pages.php unverified password changeEPSS 0.3%CVE-2026-9273CRITICALMembership Plugin – Kadence Memberships <= 4.0.0 - Unauthenticated Password Reset Link Poisoning to Account TakeoverEPSS 0.3%CVE-2026-19361MEDIUMmacrozheng mall mall-portal getAuthCode password recoveryEPSS 0.3%CVE-2026-61181HIGHVulnerability in the Oracle Agile Product Lifecycle Management for Process product of Oracle Supply Chain (component: Product Quality ManageEPSS 0.3%CVE-2026-13020HIGHWeak Password Recovery Mechanism in Portal for ArcGISEPSS 0.3%CVE-2026-30459HIGHAn issue in the Forgot Password feature of Daylight Studio FuelCMS v1.5.2 allows unauthenticated attackers to obtain the password reset tokeEPSS 0.3%CVE-2026-72772HIGHn8n before 2.32.1 Authentication Bypass via Token ExchangeEPSS 0.3%CVE-2026-34408CRITICALAn issue was discovered in Gambio 4.9.2.0 (patched in 2024-02 v1.0.0 for GX4 v4.0.0.0 to v4.9.2.0). The password reset function can be bypasEPSS 0.3%CVE-2026-45013HIGHApostrophe has a Weak Password Recovery Mechanism for Forgotten Password and Improper Input ValidationEPSS 0.3%CVE-2026-29199HIGHphpBB before 3.3.16 is vulnerable to Host Header Injection that can lead to password rest link poisoning. When force_server_vars is disabledEPSS 0.2%CVE-2026-81905MEDIUMConcrete CMS below 9.5.3 does not enforce validation-hash type on redemption, allowing a hash issued for one purpose to be redeemed for another.EPSS 0.2%CVE-2026-35676HIGHphpMyFAQ - Unauthenticated Password Reset via User Password Update EndpointEPSS 0.2%CVE-2020-37158HIGHAVideo Platform 8.1 - Cross Site Request Forgery (Password Reset)EPSS 0.2%CVE-2026-22723MEDIUMUAA User Token Revocation logic errorEPSS 0.2%CVE-2026-9609MEDIUMQianFox FoxCMS Admin.php edit password recoveryEPSS 0.2%CVE-2025-56748MEDIUMCreativeitem Academy LMS up to and including 5.13 uses predictable password reset tokens based on Base64 encoded templates without rate limiEPSS 0.2%CVE-2026-40585HIGHblueprintUE: Password Reset Tokens Have No Expiry WindowEPSS 0.2%