CWE-640— Weak Password Recovery Mechanism for Forgotten Password
The product contains a mechanism for users to recover or change their passwords without knowing the original password, but the mechanism is weak.— MITRE CWE catalog
305 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-640page 3 of 7
- CVE-2021-36436MEDIUMCVSS 5.3EG 5.32023-04-20
An issue in Mobicint Backend for Credit Unions v3 allows attackers to retrieve partial email addresses and user entered information via submission to the forgotten-password endpoint.
- CVE-2021-36708HIGHCVSS 7.5EG 7.52021-08-06
In ProLink PRC2402M V1.0.18 and older, the set_sys_init function in the login.cgi binary allows an attacker to reset the password to the administrative interface of the router.
- CVE-2021-36804MEDIUMCVSS 5.4EG 5.42021-08-04
Akaunting version 2.1.12 and earlier suffers from a password reset spoofing vulnerability, wherein an attacker can proxy password reset requests through a running Akaunting instance, if that attacker knows the target's e-mail address. This…
- CVE-2021-37541MEDIUMCVSS 6.1EG 6.12021-08-06
In JetBrains Hub before 2021.1.13402, HTML injection in the password reset email was possible.
- CVE-2021-37693MEDIUMCVSS 5.3EG 5.32021-08-13
Discourse is an open-source platform for community discussion. In Discourse before versions 2.7.8 and 2.8.0.beta4, when adding additional email addresses to an existing account on a Discourse site an email token is generated as part of the…
- CVE-2021-39899LOWCVSS 2.9EG 2.92021-10-04
In all versions of GitLab CE/EE, an attacker with physical access to a user’s machine may brute force the user’s password via the change password function. There is a rate limit in place, but the attack may still be conducted by steali…
- CVE-2021-39919MEDIUMCVSS 4.4EG 4.42021-12-13
In all versions of GitLab CE/EE starting version 14.0 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2, the reset password token and new user email token are accidentally logged wh…
- CVE-2021-41694CRITICALCVSS 9.8EG 9.82021-12-09
An Incorrect Access Control vulnerability exists in Premiumdatingscript 4.2.7.7 via the password change procedure in requests\user.php.
- CVE-2021-43498HIGHCVSS 7.5EG 7.52022-04-08
An Access Control vulnerability exists in ATutor 2.2.4 in password_reminder.php when the g, id, h, form_password_hidden, and form_change HTTP POST parameters are set.
- CVE-2021-44037HIGHCVSS 7.5EG 7.52021-11-19
Team Password Manager (aka TeamPasswordManager) before 10.135.236 allows password-reset poisoning.
- CVE-2021-44839MEDIUMCVSS 6.5EG 6.52022-01-18
An issue was discovered in Delta RM 1.2. It is possible to request a new password for any other account using the account ID. Using the /listes/DTsendmaildata/adm_utilisateur/send-mail.json endpoint, a user can send a JSON array with user …
- CVE-2022-0777HIGHCVSS 7.5EG 7.52022-03-01
Weak Password Recovery Mechanism for Forgotten Password in GitHub repository microweber/microweber prior to 1.3.
- CVE-2022-1073CRITICALCVSS 7.3EG 9.82022-03-29
A vulnerability was found in Automatic Question Paper Generator 1.0. It has been declared as critical. An attack leads to privilege escalation. The attack can be launched remotely.
- CVE-2022-22691MEDIUMCVSS 6.8EG 6.82022-01-18
The password reset component deployed within Umbraco uses the hostname supplied within the request host header when building a password reset URL. It may be possible to manipulate the URL sent to Umbraco users when so that it points to the…
- CVE-2022-23172MEDIUMCVSS 5.5EG 5.52022-07-06
An attacker can access to "Forgot my password" button, as soon as he puts users is valid in the system, the system would issue a message that a password reset email had been sent to user. This way you can verify which users are in the syst…
- CVE-2022-23619MEDIUMCVSS 5.3EG 5.32022-02-09
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In affected versions it's possible to guess if a user has an account on the wiki by using the "Forgot your password" form, even if the…
- CVE-2022-23855CRITICALCVSS 9.8EG 9.82022-01-24
An issue was discovered in Saviynt Enterprise Identity Cloud (EIC) 5.5 SP2.x. An authentication bypass in ECM/maintenance/forgotpasswordstep1 allows an unauthenticated user to reset passwords and login as any local account.
- CVE-2022-24892MEDIUMCVSS 6.4EG 6.42022-04-28
Shopware is an open source e-commerce software platform. Starting with version 5.0.4 and before version 5.7.9, multiple tokens for password reset can be requested. All tokens can be used to change the password. This makes it possible for a…
- CVE-2022-25027HIGHCVSS 7.5EG 7.52023-01-12
The Forgotten Password functionality of Rocket TRUfusion Portal v7.9.2.1 allows remote attackers to bypass authentication and access restricted pages by validating the user's session token when the "Password forgotten?" button is clicked.
- CVE-2022-26872HIGHCVSS 8.3EG 8.82023-01-30
AMI Megarac Password reset interception via API
- CVE-2022-27157CRITICALCVSS 9.8EG 9.82022-04-15
pearweb < 1.32 is suffers from a Weak Password Recovery Mechanism via include/users/passwordmanage.php.
- CVE-2022-29174HIGHCVSS 8.1EG 8.12022-05-17
countly-server is the server-side part of Countly, a product analytics solution. Prior to versions 22.03.7 and 21.11.4, a malicious actor who knows an account email address/username and full name specified in the database is capable of gue…
- CVE-2022-29933HIGHCVSS 8.8EG 8.82022-05-09
Craft CMS through 3.7.36 allows a remote unauthenticated attacker, who knows at least one valid username, to reset the account's password and take over the account by providing a crafted HTTP header to the application while using the passw…
- CVE-2022-30332MEDIUMCVSS 5.3EG 5.32023-01-10
In Talend Administration Center 7.3.1.20200219 before TAC-15950, the Forgot Password feature provides different error messages for invalid reset attempts depending on whether the email address is associated with any account. This allows re…
- CVE-2022-34530MEDIUMCVSS 5.3EG 5.32022-08-01
An issue in the login and reset password functionality of Backdrop CMS v1.22.0 allows attackers to enumerate usernames via password reset requests and distinct responses returned based on usernames.
- CVE-2022-3485CRITICALCVSS 9.8EG 9.82022-12-12
In IFM Moneo Appliance with version up to 1.9.3 an unauthenticated remote attacker can reset the administrator password by only supplying the serial number and thus gain full control of the device.
- CVE-2022-37300CRITICALCVSS 9.8EG 9.82022-09-12
A CWE-640: Weak Password Recovery Mechanism for Forgotten Password vulnerability exists that could cause unauthorized access in read and write mode to the controller when communicating over Modbus. Affected Products: EcoStruxure Control Ex…
- CVE-2022-42807MEDIUMCVSS 4.3EG 4.32023-06-23
A logic issue was addressed with improved state management. This issue is fixed in macOS Ventura 13. A user may accidentally add a participant to a Shared Album by pressing the Delete key
- CVE-2022-44004CRITICALCVSS 9.8EG 9.82022-11-16
An issue was discovered in BACKCLICK Professional 5.9.63. Due to insecure design or lack of authentication, unauthenticated attackers can complete the password-reset process for any account and set a new password.
- CVE-2022-45637CRITICALCVSS 9.8EG 9.82023-03-21
An insecure password reset issue discovered in MEGAFEIS, BOFEI DBD+ Application for IOS & Android v1.4.4 service via insecure expiry mechanism.
- CVE-2022-45782CRITICALCVSS 8.8EG 9.82023-02-01
An issue was discovered in dotCMS core 5.3.8.5 through 5.3.8.15 and 21.03 through 22.10.1. A cryptographically insecure random generation algorithm for password-reset token generation leads to account takeover.
- CVE-2022-47377CRITICALCVSS 9.8EG 9.82022-12-16
Password recovery vulnerability in SICK SIM2000ST Partnumber 2086502 with firmware version <1.13.4 allows an unprivileged remote attacker to gain access to the userlevel defined as RecoverableUserLevel by invocating the password recovery m…
- CVE-2022-47697CRITICALCVSS 9.8EG 9.82023-01-31
COMFAST (Shenzhen Sihai Zhonglian Network Technology Co., Ltd) CF-WR623N Router firmware V2.3.0.1 and before is vulnerable to Account takeover. Anyone can reset the password of the admin accounts.
- CVE-2022-50910CRITICALCVSS 9.8EG 9.82026-01-13
Beehive Forum 1.5.2 contains a host header injection vulnerability in the forgot password functionality that allows attackers to manipulate password reset requests. Attackers can inject a malicious host header to intercept password reset t…
- CVE-2023-0352CRITICALCVSS 9.1EG 9.12023-03-13
The Akuvox E11 password recovery webpage can be accessed without authentication, and an attacker could download the device key file. An attacker could then use this page to reset the password back to the default.
- CVE-2023-26615HIGHCVSS 7.5EG 7.52023-06-28
D-Link DIR-823G firmware version 1.02B05 has a password reset vulnerability, which originates from the SetMultipleActions API, allowing unauthorized attackers to reset the WEB page management password.
- CVE-2023-28202MEDIUMCVSS 5.5EG 5.52023-06-23
This issue was addressed with improved state management. This issue is fixed in iOS 16.5 and iPadOS 16.5, watchOS 9.5, tvOS 16.5, macOS Ventura 13.4. An app firewall setting may not take effect after exiting the Settings app.
- CVE-2023-28821MEDIUMCVSS 5.3EG 5.32023-04-28
Concrete CMS (previously concrete5) before 9.1 did not have a rate limit for password resets.
- CVE-2023-29145HIGHCVSS 7.8EG 7.82023-06-30
The Malwarebytes EDR 1.0.11 for Linux driver doesn't properly ensure whitelisting of executable libraries loaded by executable files, allowing arbitrary code execution. The attacker can set LD_LIBRARY_PATH, set LD_PRELOAD, or run an execut…
- CVE-2023-3007MEDIUMCVSS 6.5EG 6.52023-05-31
A vulnerability was found in ningzichun Student Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file resetPassword.php of the component Password Reset Handler. The manipulat…
- CVE-2023-30466CRITICALCVSS 9.8EG 9.82023-04-28
This vulnerability exists in Milesight 4K/H.265 Series NVR models (MS-Nxxxx-xxG, MS-Nxxxx-xxE, MS-Nxxxx-xxT, MS-Nxxxx-xxH and MS-Nxxxx-xxC), due to a weak password reset mechanism at the Milesight NVR web-based management interface. A remo…
- CVE-2023-31287HIGHCVSS 7.8EG 7.82023-04-27
An issue was discovered in Serenity Serene (and StartSharp) before 6.7.0. Password reset links are sent by email. A link contains a token that is used to reset the password. This token remains valid even after the password reset and can be…
- CVE-2023-31459HIGHCVSS 8.8EG 8.82023-05-24
A vulnerability in the Connect Mobility Router component of Mitel MiVoice Connect versions 9.6.2208.101 and earlier could allow an unauthenticated attacker with internal network access to authenticate with administrative privileges, becaus…
- CVE-2023-3222HIGHCVSS 7.5EG 7.52023-09-04
Vulnerability in the password recovery mechanism of Password Recovery plugin for Roundcube, in its 1.2 version, which could allow a remote attacker to change an existing user´s password by adding a 6-digit numeric token. An attacker could…
- CVE-2023-34357HIGHCVSS 7.8EG 7.82023-09-07
Soar Cloud Ltd. HR Portal has a weak Password Recovery Mechanism for Forgotten Password. The reset password link sent out through e-mail, and the link will remain valid after the password has been reset and after the expected expiration d…
- CVE-2023-35134HIGHCVSS 7.4EG 7.42023-07-19
Weintek Weincloud v0.13.6 could allow an attacker to reset a password with the corresponding account’s JWT token only.
- CVE-2023-35717HIGHCVSS 8.8EG 8.82024-05-03
TP-Link Tapo C210 Password Recovery Authentication Bypass Vulnerability. This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of TP-Link Tapo C210 IP cameras. Authentication is not require…
- CVE-2023-36487CRITICALCVSS 9.8EG 9.82023-06-29
The password reset function in ILIAS 7.0_beta1 through 7.20 and 8.0_beta1 through 8.1 allows remote attackers to take over the account.
- CVE-2023-4096HIGHCVSS 8.2EG 8.62023-09-19
Weak password recovery mechanism vulnerability in Fujitsu Arconte Áurea version 1.5.0.0, which exploitation could allow an attacker to perform a brute force attack on the emailed PIN number in order to change the password of a legitimate…
- CVE-2023-4214CRITICALCVSS 9.8EG 9.82023-11-18
The AppPresser plugin for WordPress is vulnerable to unauthorized password resets in versions up to, and including 4.2.5. This is due to the plugin generating too weak a reset code, and the code used to reset the password has no attempt or…
Map vulnerabilities like CWE-640 to your infrastructure
EchelonGraph correlates every CVE — across CWE-640 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →