CWE-640— Weak Password Recovery Mechanism for Forgotten Password
245 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-640page 1 of 5
- CVE-2009-5025HIGHCVSS 7.5EG 7.52020-01-15
A backdoor (aka BMSA-2009-07) was found in PyForum v1.0.3 where an attacker who knows a valid user email could force a password reset on behalf of that user.
- CVE-2012-5618CRITICALCVSS 9.8EG 9.82020-02-04
Ushahidi before 2.6.1 has insufficient entropy for forgot-password tokens.
- CVE-2012-5686CRITICALCVSS 9.8EG 9.82020-02-04
ZPanel 10.0.1 has insufficient entropy for its password reset process.
- CVE-2014-6412HIGHCVSS 8.1EG 8.12018-04-12
WordPress before 4.4 makes it easier for remote attackers to predict password-recovery tokens via a brute-force approach.
- CVE-2015-10071LOWCVSS 2.6EG 7.52023-01-19
A vulnerability was found in gitter-badger ezpublish-modern-legacy. It has been rated as problematic. This issue affects some unknown processing of the file kernel/user/forgotpassword.php. The manipulation leads to weak password recovery. …
- CVE-2017-0921HIGHCVSS 8.1EG 8.12018-07-03
GitLab Community and Enterprise Editions before 10.1.6, 10.2.6, and 10.3.4 are vulnerable to an unverified password change issue in the PasswordsController component resulting in potential account takeover if a victim's session is compromi…
- CVE-2017-1000141MEDIUMCVSS 6.5EG 6.52018-01-30
An issue was discovered in Mahara before 18.10.0. It mishandled user requests that could discontinue a user's ability to maintain their own account (changing username, changing primary email address, deleting account). The correct behavior…
- CVE-2017-12161HIGHCVSS 8.8EG 8.82018-02-21
It was found that keycloak before 3.4.2 final would permit misuse of a client-side /etc/hosts entry to spoof a URL in a password reset request. An attacker could use this flaw to craft a malicious password reset request and gain a valid re…
- CVE-2017-17097CRITICALCVSS 9.8EG 9.82018-01-02
gps-server.net GPS Tracking Software (self hosted) 2.x has a password reset procedure that immediately resets passwords upon an unauthenticated request, and then sends e-mail with a predictable (date-based) password to the admin, which mak…
- CVE-2017-2614MEDIUMCVSS 6.8EG 6.32018-07-27
When updating a password in the rhvm database the ovirt-aaa-jdbc-tool tools before 1.1.3 fail to correctly check for the current password if it is expired. This would allow access to an attacker with access to change the password on accoun…
- CVE-2017-8916HIGHCVSS 7.8EG 7.82018-01-31
In Center for Internet Security CIS-CAT Pro Dashboard before 1.0.4, an authenticated user is able to change an administrative user's e-mail address and send a forgot password email to themselves, thereby gaining administrative access.
- CVE-2018-0696HIGHCVSS 7.5EG 7.52019-02-13
OpenAM (Open Source Edition) 13.0 and later does not properly manage sessions, which allows remote authenticated attackers to change the security questions and reset the login password via unspecified vectors.
- CVE-2018-0787HIGHCVSS 8.8EG 8.82018-03-14
ASP.NET Core 1.0. 1.1, and 2.0 allow an elevation of privilege vulnerability due to how web applications that are created from templates validate web requests, aka "ASP.NET Core Elevation Of Privilege Vulnerability".
- CVE-2018-1000501CRITICALCVSS 9.8EG 9.82018-06-26
Instant Update CMS contains a Password Reset Vulnerability vulnerability in /iu-application/controllers/administration/auth.php that can result in Account Tackover. This attack appear to be exploitable via network connectivity. This vulner…
- CVE-2018-1000554CRITICALCVSS 9.8EG 9.82018-06-26
Trovebox version <= 4.0.0-rc6 contains a Unsafe password reset token generation vulnerability in user component that can result in Password reset. This attack appear to be exploitable via HTTP request. This vulnerability appears to have be…
- CVE-2018-1000812HIGHCVSS 8.1EG 8.12018-12-20
Artica Integria IMS version 5.0 MR56 Package 58, likely earlier versions contains a CWE-640: Weak Password Recovery Mechanism for Forgotten Password vulnerability in Password recovery process, line 45 of general/password_recovery.php that …
- CVE-2018-10081CRITICALCVSS 9.8EG 9.82018-04-13
CMS Made Simple (CMSMS) through 2.2.6 contains an admin password reset vulnerability because data values are improperly compared, as demonstrated by a hash beginning with the "0e" substring.
- CVE-2018-10210MEDIUMCVSS 5.3EG 5.32018-04-25
An issue was discovered in Vaultize Enterprise File Sharing 17.05.31. Enumeration of users is possible through the password-reset feature.
- CVE-2018-11134HIGHCVSS 8.8EG 8.82018-05-31
In order to perform actions that requires higher privileges, the Quest KACE System Management Appliance 8.0.318 relies on a message queue managed that runs with root privileges and only allows a set of commands. One of the available comman…
- CVE-2018-12315MEDIUMCVSS 6.5EG 6.52018-12-04
Missing verification of a password in ASUSTOR ADM version 3.1.1 allows attackers to change account passwords without entering the current password.
- CVE-2018-12421CRITICALCVSS 9.8EG 9.82018-06-14
LTB (aka LDAP Tool Box) Self Service Password before 1.3 allows a change to a user password (without knowing the old password) via a crafted POST request, because the ldap_bind return value is mishandled and the PHP data type is not constr…
- CVE-2018-12579HIGHCVSS 8.1EG 8.12018-08-20
An issue was discovered in OXID eShop Enterprise Edition before 5.3.8, 6.0.x before 6.0.3, and 6.1.x before 6.1.0; Professional Edition before 4.10.8, 5.x and 6.0.x before 6.0.3, and 6.1.x before 6.1.0; and Community Edition before 4.10.8,…
- CVE-2018-16529CRITICALCVSS 9.8EG 9.82019-03-28
A password reset vulnerability has been discovered in Forcepoint Email Security 8.5.x. The password reset URL can be used after the intended expiration period or after the URL has already been used to reset a password.
- CVE-2018-16988CRITICALCVSS 9.8EG 9.82019-05-02
An issue was discovered in Open XDMoD through 7.5.0. An authentication bypass (account takeover) exists due to a weak password reset mechanism. A brute-force attack against an MD5 rid value requires only 600 guesses in the plausible situat…
- CVE-2018-17298CRITICALCVSS 9.8EG 9.82018-09-21
An issue was discovered in Enalean Tuleap before 10.5. Reset password links are not invalidated after a user changes its password.
- CVE-2018-17401HIGHCVSS 8.8EG 8.82018-09-23
The PhonePe wallet (aka com.PhonePe.app) application 3.0.6 through 3.3.26 for Android might allow attackers to perform Account Takeover attacks by exploiting its Forgot Password feature. NOTE: the vendor says that, to exploit this, the us…
- CVE-2018-17881CRITICALCVSS 9.8EG 9.82018-10-03
On D-Link DIR-823G 2018-09-19 devices, the GoAhead configuration allows /HNAP1 SetPasswdSettings commands without authentication to trigger an admin password change.
- CVE-2018-18871CRITICALCVSS 9.8EG 9.82018-12-20
Missing password verification in the web interface on Gigaset Maxwell Basic VoIP phones with firmware 2.22.7 would allow a remote attacker (in the same network as the device) to change the admin password without authentication (and without…
- CVE-2018-19488CRITICALCVSS 9.8EG 9.82019-03-21
The WP-jobhunt plugin before version 2.4 for WordPress does not control AJAX requests sent to the cs_reset_pass() function through the admin-ajax.php file, which allows remote unauthenticated attackers to reset the password of a user's acc…
- CVE-2018-7809CRITICALCVSS 9.8EG 9.82018-11-30
An Unverified Password Change vulnerability exists in the embedded web servers in all Modicon M340, Premium, Quantum PLCs and BMXNOR0200 which could allow an unauthenticated remote user to access the password delete function of the web ser…
- CVE-2018-7811CRITICALCVSS 9.8EG 9.82018-11-30
An Unverified Password Change vulnerability exists in the embedded web servers in all Modicon M340, Premium, Quantum PLCs and BMXNOR0200 which could allow an unauthenticated remote user to access the change password function of the web ser…
- CVE-2018-8916MEDIUMCVSS 6.3EG 8.82018-06-08
Unverified password change vulnerability in Change Password in Synology DiskStation Manager (DSM) before 6.2-23739 allows remote authenticated users to reset password without verification.
- CVE-2019-10270HIGHCVSS 8.8EG 8.82019-06-21
An arbitrary password reset issue was discovered in the Ultimate Member plugin 2.39 for WordPress. It is possible (due to lack of verification and correlation between the reset password key sent by mail and the user_id parameter) to reset …
- CVE-2019-10641CRITICALCVSS 9.8EG 9.82019-04-17
Contao before 3.5.39 and 4.x before 4.7.3 has a Weak Password Recovery Mechanism for a Forgotten Password.
- CVE-2019-11393CRITICALCVSS 9.8EG 9.82019-04-22
An issue was discovered in /admin/users/update in M/Monit before 3.7.3. It allows unprivileged users to escalate their privileges to an administrator by requesting a password change and specifying the admin parameter.
- CVE-2019-11414HIGHCVSS 8.8EG 8.82019-04-22
An issue was discovered on Intelbras IWR 3000N 1.5.0 devices. When the administrator password is changed from a certain client IP address, administrative authorization remains available to any client at that IP address, leading to complete…
- CVE-2019-12476MEDIUMCVSS 6.8EG 6.82019-06-17
An authentication bypass vulnerability in the password reset functionality in Zoho ManageEngine ADSelfService Plus before 5.0.6 allows an attacker with physical access to gain a shell with SYSTEM privileges via the restricted thick client …
- CVE-2019-12943HIGHCVSS 8.1EG 8.12019-09-10
TTLock devices do not properly restrict password-reset attempts, leading to incorrect access control and disclosure of sensitive information about valid account names.
- CVE-2019-13240MEDIUMCVSS 5.9EG 5.92019-07-10
An issue was discovered in GLPI before 9.4.1. After a successful password reset by a user, it is possible to change that user's password again during the next 24 hours without any information except the associated email address.
- CVE-2019-14955MEDIUMCVSS 5.3EG 5.32019-10-01
In JetBrains Hub versions earlier than 2018.4.11436, there was no option to force a user to change the password and no password expiration policy was implemented.
- CVE-2019-15749MEDIUMCVSS 6.5EG 6.52019-10-07
SITOS six Build v6.2.1 allows a user to change their password and recovery email address without requiring them to confirm the change with their old password. This would allow an attacker with access to the victim's account (e.g., via XSS …
- CVE-2019-15929CRITICALCVSS 9.8EG 9.82019-10-24
In Craft CMS through 3.1.7, the elevated session password prompt was not being rate limited like normal login forms, leading to the possibility of a brute force attempt on them.
- CVE-2019-17392CRITICALCVSS 9.8EG 9.82019-11-26
Progress Sitefinity 12.1 has a Weak Password Recovery Mechanism for a Forgotten Password because the HTTP Host header is mishandled.
- CVE-2019-18818CRITICALCVSS 9.8EG 9.82019-11-07
strapi before 3.0.0-beta.17.5 mishandles password resets within packages/strapi-admin/controllers/Auth.js and packages/strapi-plugin-users-permissions/controllers/Auth.js.
- CVE-2019-19844CRITICALCVSS 9.8EG 9.82019-12-18
Django before 1.11.27, 2.x before 2.2.9, and 3.x before 3.0.1 allows account takeover. A suitably crafted email address (that is equal to an existing user's email address after case transformation of Unicode characters) would allow an atta…
- CVE-2019-20004HIGHCVSS 8.8EG 8.82020-01-05
An issue was discovered on Intelbras IWR 3000N 1.8.7 devices. When the administrator password is changed from a certain client IP address, administrative authorization remains available to any client at that IP address, leading to complete…
- CVE-2019-3787HIGHCVSS 8.3EG 8.32019-06-19
Cloud Foundry UAA, versions prior to 73.0.0, falls back to appending “unknown.org” to a user's email address when one is not provided and the user name does not contain an @ character. This domain is held by a private company, which le…
- CVE-2019-6560CRITICALCVSS 9.1EG 9.12020-03-23
In Auto-Maskin RP210E Versions 3.7 and prior, DCU210E Versions 3.7 and prior and Marine Observer Pro (Android App), the software contains a mechanism for users to recover or change their passwords without knowing the original password, but…
- CVE-2020-11027MEDIUMCVSS 6.1EG 6.12020-04-30
In affected versions of WordPress, a password reset link emailed to a user does not expire upon changing the user password. Access would be needed to the email account of the user by a malicious party for successful execution. This has bee…
- CVE-2020-12067HIGHCVSS 7.5EG 7.52022-12-26
In Pilz PMC programming tool 3.x before 3.5.17 (based on CODESYS Development System), a user's password may be changed by an attacker without knowledge of the current password.
Map vulnerabilities like CWE-640 to your infrastructure
EchelonGraph correlates every CVE — across CWE-640 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →