← Back
CWE-640

317 CVEs • Abstraction: Base • Likelihood of Exploit: High

Weak Password Recovery Mechanism for Forgotten Password

The product contains a mechanism for users to recover or change their passwords without knowing the original password, but the mechanism is weak.

JSON object

Loading...

CVEs (317)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Teampasswordmanager
1Team Password Manager
Jun 17, 2026
Nov 19, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Team Password Manager (aka TeamPasswordManager) before 10.135.236 allows password-reset poisoning.
1Gitlab
1Gitlab
Jun 17, 2026
Oct 4, 2021
N/A· v4
4.2 MEDIUM· v3
1.9 LOW· v2
In all versions of GitLab CE/EE, an attacker with physical access to a user’s machine may brute force the user’s password via the change password function. There is a rate limit in place, but the attack may still be cond...Show more
In all versions of GitLab CE/EE, an attacker with physical access to a user’s machine may brute force the user’s password via the change password function. There is a rate limit in place, but the attack may still be conducted by stealing the session id from the physical compromise of the account and splitting the attack over several IP addresses and passing in the compromised session value from these various locations.Show less
1Salesagility
1Suitecrm
Jun 17, 2026
Sep 29, 2021
N/A· v4
8.0 HIGH· v3
6.0 MEDIUM· v2
In “SuiteCRM” application, v7.1.7 through v7.10.31 and v7.11-beta through v7.11.20 fail to properly invalidate password reset links that is associated with a deleted user id, which makes it possible for account takeover...Show more
In “SuiteCRM” application, v7.1.7 through v7.10.31 and v7.11-beta through v7.11.20 fail to properly invalidate password reset links that is associated with a deleted user id, which makes it possible for account takeover of any newly created user with the same user id.Show less
1Otrs
1Otrs
Jun 17, 2026
Sep 6, 2021
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Malicious attacker is able to find out valid user logins by using the "lost password" feature. This issue affects: OTRS AG ((OTRS)) Community Edition version 6.0.1 and later versions. OTRS AG OTRS 7.0.x version 7.0.28 an...Show more
Malicious attacker is able to find out valid user logins by using the "lost password" feature. This issue affects: OTRS AG ((OTRS)) Community Edition version 6.0.1 and later versions. OTRS AG OTRS 7.0.x version 7.0.28 and prior versions.Show less
1Dolibarr
1Dolibarr
Jun 17, 2026
Aug 17, 2021
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
In “Dolibarr” application, v2.8.1 to v13.0.2 are vulnerable to account takeover via password reset functionality. A low privileged attacker can reset the password of any user in the application using the password reset l...Show more
In “Dolibarr” application, v2.8.1 to v13.0.2 are vulnerable to account takeover via password reset functionality. A low privileged attacker can reset the password of any user in the application using the password reset link the user received through email when requested for a forgotten password.Show less
1Discourse
1Discourse
Jun 17, 2026
Aug 13, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Discourse is an open-source platform for community discussion. In Discourse before versions 2.7.8 and 2.8.0.beta4, when adding additional email addresses to an existing account on a Discourse site an email token is gener...Show more
Discourse is an open-source platform for community discussion. In Discourse before versions 2.7.8 and 2.8.0.beta4, when adding additional email addresses to an existing account on a Discourse site an email token is generated as part of the email verification process. Deleting the additional email address does not invalidate an unused token which can then be used in other contexts, including reseting a password.Show less
1Jetbrains
1Hub
Jun 17, 2026
Aug 6, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
In JetBrains Hub before 2021.1.13402, HTML injection in the password reset email was possible.
1Prolink
1Prc2402m Firmware
Jun 17, 2026
Aug 6, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
In ProLink PRC2402M V1.0.18 and older, the set_sys_init function in the login.cgi binary allows an attacker to reset the password to the administrative interface of the router.
1Jetbrains
1Hub
Jun 17, 2026
Aug 6, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
In JetBrains Hub before 2021.1.13389, account takeover was possible during password reset.
1Akaunting
1Akaunting
Jun 17, 2026
Aug 4, 2021
N/A· v4
8.1 HIGH· v3
5.8 MEDIUM· v2
Akaunting version 2.1.12 and earlier suffers from a password reset spoofing vulnerability, wherein an attacker can proxy password reset requests through a running Akaunting instance, if that attacker knows the target's e...Show more
Akaunting version 2.1.12 and earlier suffers from a password reset spoofing vulnerability, wherein an attacker can proxy password reset requests through a running Akaunting instance, if that attacker knows the target's e-mail address. This issue was fixed in version 2.1.13 of the product. Please note that this issue is ultimately caused by the defaults provided by the Laravel framework, specifically how proxy headers are handled with respect to multi-tenant implementations. In other words, while this is not technically a vulnerability in Laravel, this default configuration is very likely to lead to practically identical identical vulnerabilities in Laravel projects that implement multi-tenant applications.Show less
1Liferay
2Dxp
Liferay Portal
Jun 17, 2026
Aug 3, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Insecure default configuration in Liferay Portal 6.2.3 through 7.3.2, and Liferay DXP before 7.3, allows remote attackers to enumerate user email address via the forgot password functionality. The portal.property login.s...Show more
Insecure default configuration in Liferay Portal 6.2.3 through 7.3.2, and Liferay DXP before 7.3, allows remote attackers to enumerate user email address via the forgot password functionality. The portal.property login.secure.forgot.password should be defaulted to true.Show less
1Schneider Electric
5Powerlogic Pm5560 Firmware
Powerlogic Pm5561 FirmwarePowerlogic Pm5562 Firmware+2 more
Jun 17, 2026
Jun 11, 2021
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
A CWE-640: Weak Password Recovery Mechanism for Forgotten Password vulnerability exists in PowerLogic PM55xx, PowerLogic PM8ECC, PowerLogic EGX100 and PowerLogic EGX300 (see security notification for version infromation)...Show more
A CWE-640: Weak Password Recovery Mechanism for Forgotten Password vulnerability exists in PowerLogic PM55xx, PowerLogic PM8ECC, PowerLogic EGX100 and PowerLogic EGX300 (see security notification for version infromation) that could allow an attacker administrator level access to a device.Show less
1Seceon
1Aisiem
Jun 17, 2026
Jun 8, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Seceon aiSIEM before 6.3.2 (build 585) is prone to an unauthenticated account takeover vulnerability in the Forgot Password feature. The lack of correct configuration leads to recovery of the password reset link generate...Show more
Seceon aiSIEM before 6.3.2 (build 585) is prone to an unauthenticated account takeover vulnerability in the Forgot Password feature. The lack of correct configuration leads to recovery of the password reset link generated via the password reset functionality, and thus an unauthenticated attacker can set an arbitrary password for any user.Show less
1Schneider Electric
16Mcsesm043f23f0 Firmware
Mcsesm053f1cs0 FirmwareMcsesm053f1cu0 Firmware+13 more
Jun 17, 2026
May 26, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Weak Password Recovery Mechanism for Forgotten Password vulnerability exists on Modicon Managed Switch MCSESM* and MCSESP* V8.21 and prior which could cause an unauthorized password change through HTTP / HTTPS when basic...Show more
Weak Password Recovery Mechanism for Forgotten Password vulnerability exists on Modicon Managed Switch MCSESM* and MCSESP* V8.21 and prior which could cause an unauthorized password change through HTTP / HTTPS when basic user information is known by a remote attacker.Show less
1Jetbrains
1Teamcity
Jun 17, 2026
May 11, 2021
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
In JetBrains TeamCity before 2020.2.3, account takeover was potentially possible during a password reset.
1Strapi
1Strapi
Jun 17, 2026
May 6, 2021
N/A· v4
8.1 HIGH· v3
5.5 MEDIUM· v2
In Strapi through 3.6.0, the admin panel allows the changing of one's own password without entering the current password. An attacker who gains access to a valid session can use this to take over an account by changing t...Show more
In Strapi through 3.6.0, the admin panel allows the changing of one's own password without entering the current password. An attacker who gains access to a valid session can use this to take over an account by changing the password.Show less
1Netgear
16Cbr40 Firmware
R6900p FirmwareR7000 Firmware+13 more
Jun 17, 2026
Mar 23, 2021
N/A· v4
8.1 HIGH· v3
4.8 MEDIUM· v2
Certain NETGEAR devices are affected by password reset by an unauthenticated attacker. This affects RBK852 before 3.2.10.11, RBK853 before 3.2.10.11, RBR854 before 3.2.10.11, RBR850 before 3.2.10.11, RBS850 before 3.2.10...Show more
Certain NETGEAR devices are affected by password reset by an unauthenticated attacker. This affects RBK852 before 3.2.10.11, RBK853 before 3.2.10.11, RBR854 before 3.2.10.11, RBR850 before 3.2.10.11, RBS850 before 3.2.10.11, CBR40 before 2.5.0.10, R7000 before 1.0.11.116, R6900P before 1.3.2.126, R7900 before 1.0.4.38, R7960P before 1.4.1.66, R8000 before 1.0.4.66, R7900P before 1.4.1.66, R8000P before 1.4.1.66, RAX75 before 1.0.3.102, RAX80 before 1.0.3.102, and R7000P before 1.3.2.126.Show less
2Misp
Misp Project
2Misp
Misp
Jun 22, 2026
Jan 19, 2021
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
The default setting of MISP 2.4.136 did not enable the requirements (aka require_password_confirmation) to provide the previous password when changing a password.
1Dell
1Cpg Bios
Jun 17, 2026
Jan 4, 2021
N/A· v4
7.6 HIGH· v3
7.2 HIGH· v2
Select Dell Client Commercial and Consumer platforms support a BIOS password reset capability that is designed to assist authorized customers who forget their passwords. Dell is aware of unauthorized password generation...Show more
Select Dell Client Commercial and Consumer platforms support a BIOS password reset capability that is designed to assist authorized customers who forget their passwords. Dell is aware of unauthorized password generation tools that can generate BIOS recovery passwords. The tools, which are not authorized by Dell, can be used by a physically present attacker to reset BIOS passwords and BIOS-managed Hard Disk Drive (HDD) passwords. An unauthenticated attacker with physical access to the system could potentially exploit this vulnerability to bypass security restrictions for BIOS Setup configuration, HDD access and BIOS pre-boot authentication.Show less
1Terra Master
1Tos
Jun 17, 2026
Dec 24, 2020
N/A· v4
7.3 HIGH· v3
6.8 MEDIUM· v2
Email Injection in TerraMaster TOS <= 4.2.06 allows remote unauthenticated attackers to abuse the forget password functionality and achieve account takeover.