Falhas do tipo CWE-620

100 resultados

Mudança de senha não verificada

A aplicação permite que um usuário altere a senha de outro usuário sem validar adequadamente a identidade de quem está fazendo a solicitação. O atacante pode mudar a senha de contas alheias simplesmente manipulando parâmetros como ID de usuário ou email, sem precisar fornecer a senha atual ou responder a um desafio de autenticação.

Exemplo

Um formulário de "esqueci minha senha" envia um link de reset com um token previsível ou reutilizável; ou um endpoint de mudança de senha aceita qualquer user_id na requisição sem verificar se o token/sessão corresponde àquele usuário, permitindo que um atacante resete a conta de terceiros.

Como mitigar

Sempre validar que o usuário autenticado na sessão/token é o mesmo que está pedindo mudança de senha. Exigir a senha atual antes de aceitar a nova. Para fluxos de reset, gerar tokens criptograficamente fortes, com validade curta, e vincular explicitamente ao usuário específico; nunca confiar em IDs de usuário vindo do cliente sem verificação.

CVE-2025-4558CRITICALWormHole Tech GPM - Unverified Password ChangeEPSS 0.5%CVE-2024-12860CRITICALCarSpot – Dealership Wordpress Classified Theme <= 2.4.3 - Unauthenticated Arbitrary Password Reset/Account TakeoverEPSS 0.5%CVE-2026-46623HIGHOpenAM Account Takeover via Unverified Password Change in OAuth2 ModuleEPSS 0.5%CVE-2025-71328HIGHFlowise - Unverified Password Change via Account SettingsEPSS 0.5%CVE-2026-24443HIGHEventSentry < 6.0.1.20 Web Reports Unverified Password ChangeEPSS 0.5%CVE-2025-9286CRITICALAppy Pie Connect for WooCommerce <= 1.1.2 - Missing Authorization to Unauthenticated Privilege Escalation via reset_user_passwordEPSS 0.5%CVE-2023-4465LOWPoly VVX 601 Configuration File Import unverified password changeEPSS 0.5%CVE-2026-54176MEDIUMbackpack/crud: MyAccountController allows changing the login email without a current-password checkEPSS 0.5%CVE-2025-70082MEDIUMLantronix EDS3000PS Unverified Password ChangeEPSS 0.5%CVE-2023-4915MEDIUMWP User Control <= 1.5.3 - Insecure Password Reset MechanismEPSS 0.5%CVE-2024-37998CRITICALA vulnerability has been identified in CPCI85 Central Processing/Communication (All versions < V5.40), SICORE Base system (All versions < V1EPSS 0.5%CVE-2025-62425HIGHMatrix Authentication Service account password can be changed using an authenticated session without supplying the current passwordEPSS 0.4%CVE-2025-3607HIGHFrontend Login and Registration Blocks <= 1.0.8 - Authenticated (Subscriber+) Privilege Escalation via Password ResetEPSS 0.4%CVE-2024-8794MEDIUMBA Book Everything <= 1.6.20 - Unauthenticated Arbitrary User Password ResetEPSS 0.4%CVE-2025-61536HIGHFelixRiddle dev-jobs-handlebars 1.0 uses absolute password-reset (magic) links using the untrusted `req.headers.host` header and forces the EPSS 0.4%CVE-2023-4381MEDIUMUnverified Password Change in instantsoft/icms2EPSS 0.4%CVE-2026-86260MEDIUMsfturing hosp_order Password Recovery CommonUserController.java modifyPassWord unverified password changeEPSS 0.4%CVE-2026-92467HIGHmicroservices-platform through 6.0.0 Unverified Password Change via /users/passwordEPSS 0.4%CVE-2025-71337HIGHFlowise - Unverified Email Change via Account Profile EndpointEPSS 0.4%CVE-2025-67041HIGHLantronix EDS3000PS OS Command InjectionEPSS 0.4%