Falhas do tipo CWE-640

219 resultados

Mecanismo fraco de recuperação de senha

A aplicação oferece um fluxo de recuperação de senha (esqueci minha senha) que é facilmente contornável ou previsível. Um atacante pode adivinhar perguntas de segurança, interceptar links de reset, reusar tokens, ou explorar validações fracas para assumir contas alheias sem conhecer a senha original.

Exemplo

Um site envia um link de reset de senha por e-mail, mas o token nunca expira e é simplesmente o ID do usuário codificado em base64. Um atacante pode reutilizar tokens antigos ou gerar novos para qualquer usuário, resetando suas senhas à vontade.

Como mitigar

Implemente tokens de reset com alta entropia, validade curta (15-30 min), uso único, e vinculação ao IP/sessão. Valide a identidade antes do reset (OTP, e-mail de confirmação, desafio adaptativo). Registre e monitore tentativas anormais de recuperação.

CVE-2024-45980HIGHA host header injection vulnerability in MEANStore 1.0 allows attackers to obtain the password reset token via user interaction with a craftEPSS 0.4%CVE-2026-2895MEDIUMfunadmin Member.php repass password recoveryEPSS 0.4%CVE-2023-53958HIGHLDAP Tool Box Self Service Password 1.5.2 Account Takeover via HTTP Host HeaderEPSS 0.4%CVE-2024-9907MEDIUMQileCMS Verification Code Forget.php sendEmail password recoveryEPSS 0.4%CVE-2024-27899HIGHSecurity misconfiguration vulnerability in SAP NetWeaver AS Java User Management EngineEPSS 0.4%CVE-2025-62406HIGHPiwigo is vulnerable to one-click account takeover by modifying the password-reset linkEPSS 0.4%CVE-2026-71625CRITICALAn issue in slimkit plus ThinkSNS+ v.2.4 allows a remote attacker to escalate privileges via the ResetPasswordController.php componentEPSS 0.4%CVE-2025-69614CRITICALIncorrect Access Control via activation token reuse on the password-reset endpoint allowing unauthorized password resets and full account taEPSS 0.4%CVE-2024-6203HIGHHaloITSM - Password Reset PoisoningEPSS 0.4%CVE-2023-31459HIGHA vulnerability in the Connect Mobility Router component of Mitel MiVoice Connect versions 9.6.2208.101 and earlier could allow an unauthentEPSS 0.4%CVE-2020-5361MEDIUMSelect Dell Client Commercial and Consumer platforms support a BIOS password reset capability that is designed to assist authorized customerEPSS 0.4%CVE-2025-7948MEDIUMjshERP updatePwd password recoveryEPSS 0.4%CVE-2025-50594CRITICALAn issue was discovered in /Code/Websites/DanpheEMR/Controllers/Settings/SecuritySettingsController.cs in Danphe Health Hospital Management EPSS 0.4%CVE-2026-50635HIGHLimeSurvey Password Reset Host Header Injection Discloses Reset TokenEPSS 0.4%CVE-2025-8855HIGH2FA Expiry Bypass in Optimus Software's Brokerage AutomationEPSS 0.4%CVE-2024-50356NONEPress has a potential 2FA bypassEPSS 0.4%CVE-2025-3849MEDIUMYXJ2018 SpringBoot-Vue-OnlineExam studentPWD unverified password changeEPSS 0.4%CVE-2026-84699CRITICALTeam Password Manager before 14.184.308 Authentication Bypass in Password ResetEPSS 0.4%CVE-2024-24903HIGHDell Secure Connect Gateway (SCG) Policy Manager, version 5.10+, contain a weak password recovery mechanism for forgotten passwords. An adjaEPSS 0.4%CVE-2024-12295HIGHBoomBox Theme Extensions <= 1.8.0 - Authenticated (Subscriber+) Privilege Escalation via Password Reset/Account Takeover in boombox_ajax_reset_passwordEPSS 0.4%