Falhas do tipo CWE-640

219 resultados

Mecanismo fraco de recuperação de senha

A aplicação oferece um fluxo de recuperação de senha (esqueci minha senha) que é facilmente contornável ou previsível. Um atacante pode adivinhar perguntas de segurança, interceptar links de reset, reusar tokens, ou explorar validações fracas para assumir contas alheias sem conhecer a senha original.

Exemplo

Um site envia um link de reset de senha por e-mail, mas o token nunca expira e é simplesmente o ID do usuário codificado em base64. Um atacante pode reutilizar tokens antigos ou gerar novos para qualquer usuário, resetando suas senhas à vontade.

Como mitigar

Implemente tokens de reset com alta entropia, validade curta (15-30 min), uso único, e vinculação ao IP/sessão. Valide a identidade antes do reset (OTP, e-mail de confirmação, desafio adaptativo). Registre e monitore tentativas anormais de recuperação.

CVE-2025-13565MEDIUMSourceCodester Inventory Management System resetPassword.php password recoveryEPSS 0.5%CVE-2026-15479MEDIUMH3C NX15 Administrator Password Modification Endpoint modify change_passwd password recoveryEPSS 0.5%CVE-2023-35134HIGHWeintek Weincloud Weak Password Recovery Mechanism for Forgotten PasswordEPSS 0.5%CVE-2026-7655HIGHSureCart <= 4.2.3 - Unauthenticated Linked WordPress Account Takeover via Forged customer.updated WebhookEPSS 0.5%CVE-2026-27593CRITICALStatamic is vulnerable to account takeover via password reset link injectionEPSS 0.5%CVE-2024-6125HIGHLogin with phone number <= 1.7.34 - Insecure Password Reset MechanismEPSS 0.5%CVE-2026-28213CRITICALEverShop Vulnerable to Arbitrary Customer Account Takeover via Exposure of Password Reset Token in API ResponseEPSS 0.4%CVE-2025-1570HIGHDirectorist: AI-Powered Business Directory Plugin with Classified Ads Listings <= 8.1 - Privilege Escalation and Account Takeover via Weak OTPEPSS 0.4%CVE-2023-31287HIGHAn issue was discovered in Serenity Serene (and StartSharp) before 6.7.0. Password reset links are sent by email. A link contains a token thEPSS 0.4%CVE-2026-13019CRITICALMissing AuthenticationEPSS 0.4%CVE-2024-42915HIGHA host header injection vulnerability in Staff Appraisal System v1.0 allows attackers to obtain the password reset token via user interactioEPSS 0.4%CVE-2025-50433CRITICALAn issue was discovered in imonnit.com (2025-04-24) allowing malicious actors to gain escalated privileges via crafted password reset to takEPSS 0.4%CVE-2026-56308HIGHCapgo - Insufficient Authentication in Email Change EndpointEPSS 0.4%CVE-2026-86260MEDIUMsfturing hosp_order Password Recovery CommonUserController.java modifyPassWord unverified password changeEPSS 0.4%CVE-2026-28681HIGHIRRd: web UI host header injection allows password reset poisoning via attacker-controlled email linksEPSS 0.4%CVE-2026-33707CRITICALWeak Password Recovery Mechanism for Forgotten Password in chamilo/chamilo-lmsEPSS 0.4%CVE-2023-5296MEDIUMXinhu RockOA Password password recoveryEPSS 0.4%CVE-2024-38468CRITICALShenzhen Guoxin Synthesis image system before 8.3.0 allows unauthorized password resets via the resetPassword API.EPSS 0.4%CVE-2026-80196HIGHKimai before 2.58.0 Authentication Bypass via Password Reset LinkEPSS 0.4%CVE-2025-4319CRITICALImproper Access Control in Birebirsoft's SufirmamEPSS 0.4%