CWE-640— Weak Password Recovery Mechanism for Forgotten Password
245 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-640page 2 of 5
- CVE-2020-14015HIGHCVSS 7.5EG 7.52020-06-24
An issue was discovered in Navigate CMS 2.9 r1433. When performing a password reset, a user is emailed an activation code that allows them to reset their password. There is, however, a flaw when no activation code is supplied. The system w…
- CVE-2020-14016MEDIUMCVSS 5.3EG 5.32020-06-24
An issue was discovered in Navigate CMS 2.9 r1433. The forgot-password feature allows users to reset their passwords by using either their username or the email address associated with their account. However, the feature returns a not_foun…
- CVE-2020-15949HIGHCVSS 7.5EG 7.52020-11-05
Immuta v2.8.2 is affected by one instance of insecure permissions that can lead to user account takeover.
- CVE-2020-25105CRITICALCVSS 9.8EG 9.82020-09-03
eramba c2.8.1 and Enterprise before e2.19.3 has a weak password recovery token (createHash has only a million possibilities).
- CVE-2020-25728HIGHCVSS 8.8EG 8.82020-09-17
The Reset Password add-on before 1.2.0 for Alfresco has a broken algorithm (involving an increment) that allows a malicious user to change any user's account password include the admin account.
- CVE-2020-26061HIGHCVSS 7.5EG 7.52020-10-05
ClickStudios Passwordstate Password Reset Portal prior to build 8501 is affected by an authentication bypass vulnerability. The ResetPassword function does not validate whether the user has successfully authenticated using security questio…
- CVE-2020-27179CRITICALCVSS 9.8EG 9.82020-10-27
konzept-ix publiXone before 2020.015 allows attackers to take over arbitrary user accounts by crafting password-reset tokens.
- CVE-2020-27408HIGHCVSS 7.5EG 7.52020-12-04
OpenSIS Community Edition through 7.6 is affected by incorrect access controls for the file ResetUserInfo.php that allow an unauthenticated attacker to change the password of arbitrary users.
- CVE-2020-28186HIGHCVSS 7.3EG 7.32020-12-24
Email Injection in TerraMaster TOS <= 4.2.06 allows remote unauthenticated attackers to abuse the forget password functionality and achieve account takeover.
- CVE-2020-37158MEDIUMCVSS 5.3EG 5.32026-02-11
AVideo Platform 8.1 contains a cross-site request forgery vulnerability that allows attackers to reset user passwords by exploiting the password recovery mechanism. Attackers can craft malicious requests to the recoverPass endpoint using t…
- CVE-2020-37172MEDIUMCVSS 5.3EG 5.32026-02-11
AVideo Platform 8.1 contains a cross-site request forgery vulnerability that allows attackers to reset user passwords by exploiting the password recovery mechanism. Attackers can craft malicious requests to the recoverPass endpoint using t…
- CVE-2020-5361MEDIUMCVSS 5.1EG 5.12021-01-04
Select Dell Client Commercial and Consumer platforms support a BIOS password reset capability that is designed to assist authorized customers who forget their passwords. Dell is aware of unauthorized password generation tools that can gene…
- CVE-2020-5899HIGHCVSS 7.8EG 7.82020-07-01
In NGINX Controller 3.0.0-3.4.0, recovery code required to change a user's password is transmitted and stored in the database in plain text, which allows an attacker who can intercept the database connection or have read access to the data…
- CVE-2020-7245CRITICALCVSS 9.8EG 9.82020-01-23
Incorrect username validation in the registration process of CTFd v2.0.0 - v2.2.2 allows an attacker to take over an arbitrary account if the username is known and emails are enabled on the CTFd instance. To exploit the vulnerability, one …
- CVE-2021-22731CRITICALCVSS 9.8EG 9.82021-05-26
Weak Password Recovery Mechanism for Forgotten Password vulnerability exists on Modicon Managed Switch MCSESM* and MCSESP* V8.21 and prior which could cause an unauthorized password change through HTTP / HTTPS when basic user information i…
- CVE-2021-22763CRITICALCVSS 9.8EG 9.82021-06-11
A CWE-640: Weak Password Recovery Mechanism for Forgotten Password vulnerability exists in PowerLogic PM55xx, PowerLogic PM8ECC, PowerLogic EGX100 and PowerLogic EGX300 (see security notification for version infromation) that could allow a…
- CVE-2021-25323CRITICALCVSS 9.1EG 9.12021-01-19
The default setting of MISP 2.4.136 did not enable the requirements (aka require_password_confirmation) to provide the previous password when changing a password.
- CVE-2021-25957HIGHCVSS 8.8EG 8.82021-08-17
In “Dolibarr” application, v2.8.1 to v13.0.2 are vulnerable to account takeover via password reset functionality. A low privileged attacker can reset the password of any user in the application using the password reset link the user re…
- CVE-2021-25961HIGHCVSS 8.0EG 8.02021-09-29
In “SuiteCRM” application, v7.1.7 through v7.10.31 and v7.11-beta through v7.11.20 fail to properly invalidate password reset links that is associated with a deleted user id, which makes it possible for account takeover of any newly cr…
- CVE-2021-27654HIGHCVSS 7.8EG 7.82022-01-28
Forgotten password reset functionality for local accounts can be used to bypass local authentication checks.
- CVE-2021-28128HIGHCVSS 8.1EG 8.12021-05-06
In Strapi through 3.6.0, the admin panel allows the changing of one's own password without entering the current password. An attacker who gains access to a valid session can use this to take over an account by changing the password.
- CVE-2021-28293CRITICALCVSS 9.8EG 9.82021-06-08
Seceon aiSIEM before 6.3.2 (build 585) is prone to an unauthenticated account takeover vulnerability in the Forgot Password feature. The lack of correct configuration leads to recovery of the password reset link generated via the password …
- CVE-2021-29038MEDIUMCVSS 6.3EG 6.32024-02-20
Liferay Portal 7.2.0 through 7.3.5, and older unsupported versions, and Liferay DXP 7.3 before fix pack 1, 7.2 before fix pack 17, and older unsupported versions does not obfuscate password reminder answers on the page, which allows attack…
- CVE-2021-29080HIGHCVSS 8.1EG 8.12021-03-23
Certain NETGEAR devices are affected by password reset by an unauthenticated attacker. This affects RBK852 before 3.2.10.11, RBK853 before 3.2.10.11, RBR854 before 3.2.10.11, RBR850 before 3.2.10.11, RBS850 before 3.2.10.11, CBR40 before 2…
- CVE-2021-31912HIGHCVSS 8.8EG 8.82021-05-11
In JetBrains TeamCity before 2020.2.3, account takeover was potentially possible during a password reset.
- CVE-2021-33321HIGHCVSS 7.5EG 7.52021-08-03
Insecure default configuration in Liferay Portal 6.2.3 through 7.3.2, and Liferay DXP before 7.3, allows remote attackers to enumerate user email address via the forgot password functionality. The portal.property login.secure.forgot.passwo…
- CVE-2021-36095MEDIUMCVSS 5.3EG 5.32021-09-06
Malicious attacker is able to find out valid user logins by using the "lost password" feature. This issue affects: OTRS AG ((OTRS)) Community Edition version 6.0.1 and later versions. OTRS AG OTRS 7.0.x version 7.0.28 and prior versions.
- CVE-2021-36209CRITICALCVSS 9.8EG 9.82021-08-06
In JetBrains Hub before 2021.1.13389, account takeover was possible during password reset.
- CVE-2021-36436MEDIUMCVSS 5.3EG 5.32023-04-20
An issue in Mobicint Backend for Credit Unions v3 allows attackers to retrieve partial email addresses and user entered information via submission to the forgotten-password endpoint.
- CVE-2021-36708HIGHCVSS 7.5EG 7.52021-08-06
In ProLink PRC2402M V1.0.18 and older, the set_sys_init function in the login.cgi binary allows an attacker to reset the password to the administrative interface of the router.
- CVE-2021-36804MEDIUMCVSS 5.4EG 5.42021-08-04
Akaunting version 2.1.12 and earlier suffers from a password reset spoofing vulnerability, wherein an attacker can proxy password reset requests through a running Akaunting instance, if that attacker knows the target's e-mail address. This…
- CVE-2021-37541MEDIUMCVSS 6.1EG 6.12021-08-06
In JetBrains Hub before 2021.1.13402, HTML injection in the password reset email was possible.
- CVE-2021-37693MEDIUMCVSS 5.3EG 5.32021-08-13
Discourse is an open-source platform for community discussion. In Discourse before versions 2.7.8 and 2.8.0.beta4, when adding additional email addresses to an existing account on a Discourse site an email token is generated as part of the…
- CVE-2021-39899LOWCVSS 2.9EG 2.92021-10-04
In all versions of GitLab CE/EE, an attacker with physical access to a user’s machine may brute force the user’s password via the change password function. There is a rate limit in place, but the attack may still be conducted by steali…
- CVE-2021-39919MEDIUMCVSS 4.4EG 4.42021-12-13
In all versions of GitLab CE/EE starting version 14.0 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2, the reset password token and new user email token are accidentally logged wh…
- CVE-2021-41694CRITICALCVSS 9.8EG 9.82021-12-09
An Incorrect Access Control vulnerability exists in Premiumdatingscript 4.2.7.7 via the password change procedure in requests\user.php.
- CVE-2021-43498HIGHCVSS 7.5EG 7.52022-04-08
An Access Control vulnerability exists in ATutor 2.2.4 in password_reminder.php when the g, id, h, form_password_hidden, and form_change HTTP POST parameters are set.
- CVE-2021-44037HIGHCVSS 7.5EG 7.52021-11-19
Team Password Manager (aka TeamPasswordManager) before 10.135.236 allows password-reset poisoning.
- CVE-2021-44839MEDIUMCVSS 6.5EG 6.52022-01-18
An issue was discovered in Delta RM 1.2. It is possible to request a new password for any other account using the account ID. Using the /listes/DTsendmaildata/adm_utilisateur/send-mail.json endpoint, a user can send a JSON array with user …
- CVE-2022-0777HIGHCVSS 7.5EG 7.52022-03-01
Weak Password Recovery Mechanism for Forgotten Password in GitHub repository microweber/microweber prior to 1.3.
- CVE-2022-1073HIGHCVSS 7.3EG 9.82022-03-29
A vulnerability was found in Automatic Question Paper Generator 1.0. It has been declared as critical. An attack leads to privilege escalation. The attack can be launched remotely.
- CVE-2022-22691MEDIUMCVSS 6.8EG 6.82022-01-18
The password reset component deployed within Umbraco uses the hostname supplied within the request host header when building a password reset URL. It may be possible to manipulate the URL sent to Umbraco users when so that it points to the…
- CVE-2022-23172MEDIUMCVSS 5.5EG 4.32022-07-06
An attacker can access to "Forgot my password" button, as soon as he puts users is valid in the system, the system would issue a message that a password reset email had been sent to user. This way you can verify which users are in the syst…
- CVE-2022-23619MEDIUMCVSS 5.3EG 5.32022-02-09
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In affected versions it's possible to guess if a user has an account on the wiki by using the "Forgot your password" form, even if the…
- CVE-2022-23855CRITICALCVSS 9.8EG 9.82022-01-24
An issue was discovered in Saviynt Enterprise Identity Cloud (EIC) 5.5 SP2.x. An authentication bypass in ECM/maintenance/forgotpasswordstep1 allows an unauthenticated user to reset passwords and login as any local account.
- CVE-2022-24892MEDIUMCVSS 6.4EG 6.42022-04-28
Shopware is an open source e-commerce software platform. Starting with version 5.0.4 and before version 5.7.9, multiple tokens for password reset can be requested. All tokens can be used to change the password. This makes it possible for a…
- CVE-2022-25027HIGHCVSS 7.5EG 7.52023-01-12
The Forgotten Password functionality of Rocket TRUfusion Portal v7.9.2.1 allows remote attackers to bypass authentication and access restricted pages by validating the user's session token when the "Password forgotten?" button is clicked.
- CVE-2022-26872HIGHCVSS 8.3EG 8.82023-01-30
AMI Megarac Password reset interception via API
- CVE-2022-27157CRITICALCVSS 9.8EG 9.82022-04-15
pearweb < 1.32 is suffers from a Weak Password Recovery Mechanism via include/users/passwordmanage.php.
- CVE-2022-29174HIGHCVSS 8.1EG 8.12022-05-17
countly-server is the server-side part of Countly, a product analytics solution. Prior to versions 22.03.7 and 21.11.4, a malicious actor who knows an account email address/username and full name specified in the database is capable of gue…
Map vulnerabilities like CWE-640 to your infrastructure
EchelonGraph correlates every CVE — across CWE-640 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →