Falhas do tipo CWE-640

219 resultados

Mecanismo fraco de recuperação de senha

A aplicação oferece um fluxo de recuperação de senha (esqueci minha senha) que é facilmente contornável ou previsível. Um atacante pode adivinhar perguntas de segurança, interceptar links de reset, reusar tokens, ou explorar validações fracas para assumir contas alheias sem conhecer a senha original.

Exemplo

Um site envia um link de reset de senha por e-mail, mas o token nunca expira e é simplesmente o ID do usuário codificado em base64. Um atacante pode reutilizar tokens antigos ou gerar novos para qualquer usuário, resetando suas senhas à vontade.

Como mitigar

Implemente tokens de reset com alta entropia, validade curta (15-30 min), uso único, e vinculação ao IP/sessão. Valide a identidade antes do reset (OTP, e-mail de confirmação, desafio adaptativo). Registre e monitore tentativas anormais de recuperação.

CVE-2025-62709MEDIUMClipBucket v5 is vulnerable to password reset link manipulationEPSS 0.4%CVE-2025-50503HIGHA vulnerability in the password reset workflow of the Touch Lebanon Mobile App 2.20.2 allows an attacker to bypass the OTP reset password meEPSS 0.4%CVE-2025-29995HIGHAccount Takeover Vulnerability in CAP back office applicationEPSS 0.4%CVE-2022-42807A logic issue was addressed with improved state management. This issue is fixed in macOS Ventura 13. A user may accidentally add a participaEPSS 0.4%CVE-2024-5277MEDIUMWeak Password Recovery Mechanism in lunary-ai/lunaryEPSS 0.4%CVE-2026-9466MEDIUMTiandy Easy7 Integrated Management Platform API Endpoint updateUserPassword password recoveryEPSS 0.4%CVE-2025-14783MEDIUMEasy Digital Downloads <= 3.6.2 - Unvalidated Redirect in Password Reset Flow via edd_redirectEPSS 0.4%CVE-2025-2093LOWPHPGurukul Online Library Management System change-password.php password recoveryEPSS 0.4%CVE-2026-36438MEDIUMAn issue in Intelbras VIP-1230-D-G4 Version V2.800.00IB00C.0.T allows a remote attacker to obtain sensitive information via password reset fEPSS 0.3%CVE-2026-32103MEDIUMStudioCMS: IDOR — Admin-to-Owner Account Takeover via Password Reset Link GenerationEPSS 0.3%CVE-2026-93453HIGHSOGo before 5.12.11 Password Reset Token Interception via Origin HeaderEPSS 0.3%CVE-2025-32486CRITICALWordPress Material Dashboard plugin <= 1.4.6 - Privilege Escalation VulnerabilityEPSS 0.3%CVE-2025-43932CRITICALJobCenter through 7e7b0b2 allows account takeover via the password reset feature because SERVER_NAME is not configured and thus a reset depeEPSS 0.3%CVE-2025-43931CRITICALflask-boilerplate through a170e7c allows account takeover via the password reset feature because SERVER_NAME is not configured and thus a reEPSS 0.3%CVE-2025-64101HIGHZITADEL Vulnerable to Account Takeover via Malicious Forwarded Header InjectionEPSS 0.3%CVE-2026-53904MEDIUMAccount Denial of Service in MCOEPSS 0.3%CVE-2026-12949CRITICALWishlist Member X <= 3.34.1 - Unauthenticated Account Takeover via 'mergewith' ParameterEPSS 0.3%CVE-2024-45670MEDIUMIBM Security SOAR weak password recovery mechanismEPSS 0.3%CVE-2026-61967CRITICALWordPress miniorange otp verification plugin <= 5.5.1 - Privilege Escalation vulnerabilityEPSS 0.3%CVE-2026-72856HIGHBudibase before 3.40.0 Authentication Bypass via Tenant Owner EmailEPSS 0.3%