CVEbaza.plSłownik CWECWE-640
Common Weakness Enumeration

CWE-640

Weak Password Recovery Mechanism for Forgotten Password

Kategoria: BaseCVE: 355
Opis

Produkt zawiera mechanizm pozwalający użytkownikom odzyskać lub zmienić swoje hasła bez znajomości oryginalnego hasła, jednak mechanizm ten jest słaby. Umożliwia to atakującym obejście zabezpieczeń i uzyskanie nieautoryzowanego dostępu do kont użytkowników.

Description (EN)

The product contains a mechanism for users to recover or change their passwords without knowing the original password, but the mechanism is weak.

Podatności CVE z CWE-640 (355)
10.0
CVSS
CRITICAL
CVE-2025-4320

Oprogramowanie Sufirmam firmy Birebirsoft Software and Technology Solutions zawiera krytyczną podatność umożliwiającą obejście mechanizmu uwierzytelnienia oraz nadużycie procesu odzyskiwania zapomnianego hasła. Ocena CVSS 10.0 wskazuje na maksymalne ryzyko — atakujący nieuwierzytelniony zdalnie może przejąć kontrolę nad systemem.

pub. 2026-01-23
10.0
CVSS
CRITICAL
CVE-2025-63314

Funkcja resetowania hasła w DDSN Interactive Acora CMS v10.7.1 wykorzystuje statyczny (nielosowy) token, który nie wygasa po użyciu. Atakujący może wielokrotnie wykorzystać przechwycony token do arbitralnego zresetowania hasła i pełnego przejęcia dowolnego konta użytkownika.

pub. 2026-01-12
10.0
CVSS
CRITICAL
CVE-2024-8878

Wadliwy mechanizm odzyskiwania zapomnianego hasła w urządzeniu Riello Netman 204 pozwala atakującemu na zresetowanie hasła administratora bez uwierzytelnienia. Skutkiem jest możliwość pełnego przejęcia kontroli nad urządzeniem przez nieautoryzowaną osobę.

pub. 2024-09-25
10.0
CVSS
CRITICAL
CVE-2023-7028

Krytyczna podatność w GitLab CE/EE umożliwia wysłanie e-maila resetującego hasło na niezweryfikowany adres e-mail, co pozwala atakującemu przejąć kontrolę nad kontem ofiary. Podatność otrzymała maksymalny wynik CVSS 10.0 i jest aktywnie wykorzystywana.

pub. 2024-01-12🚩 CISA KEV⚡ EXPLOIT
9.8
CVSS
CRITICAL
CVE-2026-19632

The TranslatePress – Translate Multilingual sites with AI Translation plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.3.1 via the 'trp_get_translations_regular' AJAX action. This makes it possible for unauthenticated attackers to extract the raw administrator password-reset URL — including the plaintext reset key and login parameters stored in the translation dictionary table — enabling full administrator account takeover. This vulnerability is only exploitable when automatic string saving is enabled (the default setting) and the target administrator's profile locale is set to a published secondary language, as these conditions cause the password-reset URL to be persisted as a translatable string in the secondary-language dictionary table.

pub. 2026-08-26
9.8
CVSS
CRITICAL
CVE-2026-77264

The Automation Web Platform – Notifications and OTP for WooCommerce, Advanced Country Code plugin for WordPress is vulnerable to Authentication Bypass in versions up to, and including, 4.8.6. This is due to the handle_email_otp_return() function returning the secret magic login token in the response to a publicly accessible OTP request, rather than only delivering it to the user's email address. This makes it possible for unauthenticated attackers to log in as any user on the site, including administrators, if they know that user's email address.

pub. 2026-08-21
9.8
CVSS
CRITICAL
CVE-2026-15689

Dancer2::Plugin::Auth::Extensible versions through 0.713 for Perl allow password reset link poisoning via the request Host header in _default_email_password_reset and _default_welcome_send. Both default emails emit a link of the form `$base/login/$code`, whose authority comes from the request Host header, or from X-Forwarded-Host under behind_proxy (obtained from Dancer2's request->base function). A POST to /login carrying submit_reset and a username needs no authentication: it stores a fresh reset code against that account and mails the account holder a link to a host of the sender's choosing. The welcome mail takes the same path when the application calls create_user with email_welcome set. Through 0.711 the handlers read `request->uri_base` and `request->base` directly; Versions 0.712 and later provide an uri_base configuration key that defaults to the untrusted `request->uri_base` when unset. The default configuration with reset_password_handler enabled and the default message text, a recipient who follows the link hands a working reset code to the sender's host, which is enough to take over the account.

pub. 2026-08-15
9.8
CVSS
CRITICAL
CVE-2026-12949

The Wishlist Member plugin for WordPress is vulnerable to Account Takeover via Insufficient Verification of Data Authenticity in versions up to and including 3.34.1. This is due to the wpm_register() function validating the registration cookie only against the GET reg parameter while accepting the POST mergewith and POST wpm_id parameters without verifying that the mergewith user ID references a temporary or incomplete registrant that is bound to the current registration transaction. This makes it possible for unauthenticated attackers to take over any existing WordPress account — including administrator accounts — by supplying an arbitrary user's numeric ID as the mergewith value, which causes wp_update_user() to overwrite the target account's username (additionally written via a direct $wpdb UPDATE), password, email address, first name, and last name with attacker-controlled values, while WordPress password and email change notification emails are explicitly suppressed. When wpm_id references a non-existent membership level, no role key is added to the update payload, causing wp_update_user() to preserve the target user's existing role — including administrator — making full privilege escalation a direct consequence of the takeover.

pub. 2026-08-14
9.8
CVSS
CRITICAL
CVE-2026-61967

Unauthenticated Privilege Escalation in miniorange otp verification <= 5.5.1 versions.

pub. 2026-08-13
9.8
CVSS
CRITICAL
CVE-2026-66691

Unauthenticated Broken Access Control in Nokri <= 1.6.6 versions.

pub. 2026-08-13
9.8
CVSS
CRITICAL
CVE-2026-12571

An authentication bypass in ManageEngine DDI Central's password-reset workflow allows account takeover.

pub. 2026-08-11
9.8
CVSS
CRITICAL
CVE-2026-14364

Wtyczka TrueBooker – Appointment Booking and Scheduler System dla WordPress zawiera krytyczną podatność umożliwiającą przejęcie dowolnego konta użytkownika, w tym administratora, bez uwierzytelnienia. Błąd wynika z nieprawidłowej weryfikacji tożsamości użytkownika podczas procedury resetowania hasła.

pub. 2026-08-07
9.8
CVSS
CRITICAL
CVE-2026-13019

Podatność w Esri Portal for ArcGIS w wersji 12.1 i wcześniejszych umożliwia zdalnym, nieuwierzytelnionym atakującym dostęp do niezabezpieczonego API. Krytyczny poziom zagrożenia wynika z braku jakichkolwiek barier dostępu do funkcji wymagających ochrony.

pub. 2026-07-07
9.8
CVSS
CRITICAL
CVE-2026-37106

W DokuWiki 2025-05-14b "Librarian" zgłoszono możliwość zdalnego tworzenia kont przez funkcję rejestracji w pliku inc/auth.php. Podatność jest kwestionowana przez producenta, który wskazuje, że opisane zachowanie jest celowe i dotyczy wyłącznie niedomyślnej konfiguracji z włączoną samodzielną rejestracją użytkowników.

pub. 2026-06-30
9.8
CVSS
CRITICAL
CVE-2026-12416

Plugin Invoice Generator dla WordPress w wersjach do 1.0.0 włącznie zawiera krytyczną podatność umożliwiającą nieuwierzytelnionemu atakującemu przejęcie dowolnego konta, w tym kont administratorów. Dziura wynika z braku weryfikacji nonce i uprawnień w funkcji obsługującej reset hasła.

pub. 2026-06-24
9.8
CVSS
CRITICAL
CVE-2026-12417

Plugin SignUp & SignIn dla WordPress w wersji do 1.0.0 włącznie zawiera krytyczną podatność umożliwiającą nieuwierzytelnionemu atakującemu zmianę hasła dowolnego użytkownika, łącznie z administratorem. Skutkiem jest pełne przejęcie konta i privilege escalation na poziom administratora witryny.

pub. 2026-06-24
9.8
CVSS
CRITICAL
CVE-2026-11551

Wtyczka Branda dla WordPress w wersjach do 3.4.29 włącznie pozwala nieunauthentykowanemu atakującemu na zmianę hasła dowolnego użytkownika, w tym administratora. Podatność umożliwia pełne przejęcie konta i uzyskanie uprawnień administratora bez żadnych danych logowania.

pub. 2026-06-20
9.8
CVSS
CRITICAL
CVE-2026-28268

W Vikunja przed wersją 2.1.0 tokeny resetowania hasła nie są unieważniane po użyciu i pozostają ważne bezterminowo. Umożliwia to atakującemu, który wejdzie w posiadanie jednego tokenu, trwałe przejęcie konta w dowolnym momencie w przyszłości.

pub. 2026-02-27
9.8
CVSS
CRITICAL
CVE-2026-28213

W platformie e-commerce EverShop w wersjach wcześniejszych niż 2.1.1 funkcjonalność 'Forgot Password' zwraca token resetowania hasła bezpośrednio w odpowiedzi API. Umożliwia to atakującemu przejęcie dowolnego konta użytkownika bez żadnej autoryzacji.

pub. 2026-02-26
9.8
CVSS
CRITICAL
CVE-2026-26273

W platformie społecznościowej Known (wersje do 1.6.2 włącznie) istnieje krytyczna podatność polegająca na ujawnieniu tokena resetowania hasła w ukrytym polu formularza HTML. Umożliwia to nieuwierzytelnionemu atakującemu przejęcie dowolnego konta użytkownika bez konieczności posiadania dostępu do jego skrzynki pocztowej.

pub. 2026-02-13
Pokazano 20 z 355 podatności
Informacje
ID: CWE-640
Typ: Base
Podatności: 355
MITRE CWE ↗
← Słownik CWE