Falhas do tipo CWE-620

100 resultados

Mudança de senha não verificada

A aplicação permite que um usuário altere a senha de outro usuário sem validar adequadamente a identidade de quem está fazendo a solicitação. O atacante pode mudar a senha de contas alheias simplesmente manipulando parâmetros como ID de usuário ou email, sem precisar fornecer a senha atual ou responder a um desafio de autenticação.

Exemplo

Um formulário de "esqueci minha senha" envia um link de reset com um token previsível ou reutilizável; ou um endpoint de mudança de senha aceita qualquer user_id na requisição sem verificar se o token/sessão corresponde àquele usuário, permitindo que um atacante resete a conta de terceiros.

Como mitigar

Sempre validar que o usuário autenticado na sessão/token é o mesmo que está pedindo mudança de senha. Exigir a senha atual antes de aceitar a nova. Para fluxos de reset, gerar tokens criptograficamente fortes, com validade curta, e vincular explicitamente ao usuário específico; nunca confiar em IDs de usuário vindo do cliente sem verificação.

CVE-2025-1107CRITICALUnverified password change vulnerability in JantoEPSS 0.4%CVE-2024-13373HIGHExertio Framework <= 1.3.1 - Unauthenticated Arbitrary User Password UpdateEPSS 0.4%CVE-2025-14751HIGHUnverified Password Change in Weintek cMT X Series HMI EasyWeb ServiceEPSS 0.4%CVE-2026-54175HIGHbackpack/crud: Unverified password change in MyAccountController via mass assignmentEPSS 0.4%CVE-2024-41796MEDIUMA vulnerability has been identified in SENTRON 7KT PAC1260 Data Manager (All versions). The web interface of affected devices allows to chanEPSS 0.4%CVE-2024-12827CRITICALDWT - Directory & Listing WordPress Theme <= 3.3.6 - Unauthenticated Arbitrary User Password ResetEPSS 0.4%CVE-2025-3849MEDIUMYXJ2018 SpringBoot-Vue-OnlineExam studentPWD unverified password changeEPSS 0.4%CVE-2026-30458CRITICALAn issue in Daylight Studio FuelCMS v1.5.2 allows attackers to exfiltrate users' password reset tokens via a mail splitting attack.EPSS 0.4%CVE-2024-27715HIGHAn issue in Eskooly Free Online School management Software v.3.0 and before allows a remote attacker to escalate privileges via a crafted reEPSS 0.4%CVE-2022-2930MEDIUMUnverified Password Change in octoprint/octoprintEPSS 0.3%CVE-2025-61132HIGHA Host Header Injection vulnerability in the password reset component in levlaz braindump v0.4.14 allows remote attackers to conduct passworEPSS 0.3%CVE-2026-77644CRITICALCritical Bypass Access Control Vulnerability Reported for Windchill Risk and Reliability (WRR) Enterprise EditionEPSS 0.3%CVE-2026-42084HIGHOpenC3 COSMOS: Hijacked session token can be used to reset password for persistenceEPSS 0.3%CVE-2026-85591HIGHphpMyFAQ before 4.1.8 Authentication Bypass via Unverified Password ChangeEPSS 0.3%CVE-2026-17599MEDIUMNexus Repository 3 - Unverified Onboarding State on change-admin-password EndpointEPSS 0.3%CVE-2026-2543MEDIUMvichan-devel vichan Password Change pages.php unverified password changeEPSS 0.3%CVE-2024-51493MEDIUMAPI key access in settings without reauthentication in OctoPrintEPSS 0.3%CVE-2026-24440HIGHTenda W30E V2 Allows Password Changes Without Verifying Current PasswordEPSS 0.3%CVE-2026-44733MEDIUMOpenProject: Business Logic Error on OpenProject through PATCH request to /api/v3/users/me permits to bypass password requirementsEPSS 0.3%CVE-2025-13148HIGHIBM Aspera Orchestrator Unverified Password ChangeEPSS 0.3%