← Back
CWE-640

317 CVEs • Abstraction: Base • Likelihood of Exploit: High

Weak Password Recovery Mechanism for Forgotten Password

The product contains a mechanism for users to recover or change their passwords without knowing the original password, but the mechanism is weak.

JSON object

Loading...

CVEs (317)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Kanboard
1Kanboard
May 13, 2026
Aug 14, 2017
N/A· v4
8.8 HIGH· v3
4.0 MEDIUM· v2
An authenticated standard user could reset the password of the admin by altering form data. Affects kanboard before 1.0.46.
1Kanboard
1Kanboard
May 13, 2026
Aug 14, 2017
N/A· v4
8.8 HIGH· v3
4.0 MEDIUM· v2
An authenticated standard user could reset the password of other users (including the admin) by altering form data. Affects kanboard before 1.0.46.
1Microsoft
1Azure Active Directory Connect
May 13, 2026
Jun 29, 2017
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
Azure AD Connect Password writeback, if misconfigured during enablement, allows an attacker to reset passwords and gain unauthorized access to arbitrary on-premises AD privileged user accounts aka "Azure AD Connect Eleva...Show more
Azure AD Connect Password writeback, if misconfigured during enablement, allows an attacker to reset passwords and gain unauthorized access to arbitrary on-premises AD privileged user accounts aka "Azure AD Connect Elevation of Privilege Vulnerability."Show less
1Qnap
1Qts
May 13, 2026
Jun 15, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
QNAP QTS before 4.2.6 build 20170517 has a flaw in the change password function.
1Echatserver
1Easy Chat Server
May 13, 2026
Jun 12, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
register.ghp in EFS Software Easy Chat Server versions 2.0 to 3.1 allows remote attackers to reset arbitrary passwords via a crafted POST request to registresult.htm.
1Fortinet
1Fortiportal
May 13, 2026
May 27, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A weak password recovery vulnerability in Fortinet FortiPortal versions 4.0.0 and below allows attacker to carry out information disclosure via the Forgotten Password feature.
2Cloudfoundry
Pivotal Software
3Cf Release
Cloud Foundry Elastic RuntimeCloud Foundry Uaa
May 13, 2026
May 25, 2017
N/A· v4
3.7 LOW· v3
4.3 MEDIUM· v2
With Cloud Foundry Runtime cf-release versions v208 or earlier, UAA Standalone versions 2.2.5 or earlier and Pivotal Cloud Foundry Runtime 1.4.5 or earlier, old Password Reset Links are not expired after the user changes...Show more
With Cloud Foundry Runtime cf-release versions v208 or earlier, UAA Standalone versions 2.2.5 or earlier and Pivotal Cloud Foundry Runtime 1.4.5 or earlier, old Password Reset Links are not expired after the user changes their current email address to a new one. This vulnerability is applicable only when using the UAA internal user store for authentication. Deployments enabled for integration via SAML or LDAP are not affected.Show less
1Wordpress
1Wordpress
May 13, 2026
May 4, 2017
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
WordPress through 4.7.4 relies on the Host HTTP header for a password-reset e-mail message, which makes it easier for remote attackers to reset arbitrary passwords by making a crafted wp-login.php?action=lostpassword req...Show more
WordPress through 4.7.4 relies on the Host HTTP header for a password-reset e-mail message, which makes it easier for remote attackers to reset arbitrary passwords by making a crafted wp-login.php?action=lostpassword request and then arranging for this message to bounce or be resent, leading to transmission of the reset key to a mailbox on an attacker-controlled SMTP server. This is related to problematic use of the SERVER_NAME variable in wp-includes/pluggable.php in conjunction with the PHP mail function. Exploitation is not achievable in all cases because it requires at least one of the following: (1) the attacker can prevent the victim from receiving any e-mail messages for an extended period of time (such as 5 days), (2) the victim's e-mail system sends an autoresponse containing the original message, or (3) the victim manually composes a reply containing the original message.Show less
1Craftcms
1Craft Cms
May 13, 2026
May 1, 2017
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Craft CMS before 2.6.2976 does not prevent modification of the URL in a forgot-password email message.
1Mantisbt
1Mantisbt
May 13, 2026
Apr 16, 2017
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
MantisBT through 2.3.0 allows arbitrary password reset and unauthenticated admin access via an empty confirm_hash value to verify.php.
1Moxa
1Awk 3131a Firmware
May 13, 2026
Apr 12, 2017
N/A· v4
7.5 HIGH· v3
3.3 LOW· v2
An exploitable Cleartext Transmission of Password vulnerability exists in the Web Application functionality of Moxa AWK-3131A Wireless Access Point running firmware 1.1. The Change Password functionality of the Web Appli...Show more
An exploitable Cleartext Transmission of Password vulnerability exists in the Web Application functionality of Moxa AWK-3131A Wireless Access Point running firmware 1.1. The Change Password functionality of the Web Application transmits the password in cleartext. An attacker capable of intercepting this traffic is able to obtain valid credentials.Show less
1Emc
1Documentum Eroom
May 13, 2026
Feb 3, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
EMC Documentum eRoom version 7.4.4, EMC Documentum eRoom version 7.4.4 SP1, EMC Documentum eRoom version prior to 7.4.5 P04, EMC Documentum eRoom version prior to 7.5.0 P01 includes an unverified password change vulnerab...Show more
EMC Documentum eRoom version 7.4.4, EMC Documentum eRoom version 7.4.4 SP1, EMC Documentum eRoom version prior to 7.4.5 P04, EMC Documentum eRoom version prior to 7.5.0 P01 includes an unverified password change vulnerability that could potentially be exploited by malicious users to compromise the affected system.Show less
1Pagekit
1Pagekit
May 13, 2026
Jan 25, 2017
N/A· v4
7.5 HIGH· v3
4.3 MEDIUM· v2
An issue was discovered in Pagekit CMS before 1.0.11. In this vulnerability the remote attacker is able to reset the registered user's password, when the debug toolbar is enabled. The password is successfully recovered u...Show more
An issue was discovered in Pagekit CMS before 1.0.11. In this vulnerability the remote attacker is able to reset the registered user's password, when the debug toolbar is enabled. The password is successfully recovered using this exploit. The SecureLayer7 ID is SL7_PGKT_01.Show less
1Moodle
1Moodle
May 13, 2026
Jan 20, 2017
N/A· v4
7.3 HIGH· v3
5.0 MEDIUM· v2
In Moodle 2.x and 3.x, web service tokens are not invalidated when the user password is changed or forced to be changed.
1Bmc
1Remedy Action Request System
May 6, 2026
Dec 21, 2016
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Remedy AR System Server in BMC Remedy 8.1 SP 2, 9.0, 9.0 SP 1, and 9.1 allows attackers to reset arbitrary passwords via a blank previous password.
1Ibm
1Tealeaf Customer Experience
May 6, 2026
Sep 26, 2016
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
The web portal in IBM Tealeaf Customer Experience before 8.7.1.8847 FP10, 8.8 before 8.8.0.9049 FP9, 9.0.0 and 9.0.1 before 9.0.1.1117 FP5, 9.0.1A before 9.0.1.5108_9.0.1A FP5, 9.0.2 before 9.0.2.1223 FP3, and 9.0.2A bef...Show more
The web portal in IBM Tealeaf Customer Experience before 8.7.1.8847 FP10, 8.8 before 8.8.0.9049 FP9, 9.0.0 and 9.0.1 before 9.0.1.1117 FP5, 9.0.1A before 9.0.1.5108_9.0.1A FP5, 9.0.2 before 9.0.2.1223 FP3, and 9.0.2A before 9.0.2.5224_9.0.2A FP3 does not apply password-quality rules to password changes, which makes it easier for remote attackers to obtain access via a brute-force attack.Show less
1Ibm
1Tealeaf Customer Experience
May 6, 2026
Sep 26, 2016
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The web portal in IBM Tealeaf Customer Experience before 8.7.1.8847 FP10, 8.8 before 8.8.0.9049 FP9, 9.0.0 and 9.0.1 before 9.0.1.1117 FP5, 9.0.1A before 9.0.1.5108_9.0.1A FP5, 9.0.2 before 9.0.2.1223 FP3, and 9.0.2A bef...Show more
The web portal in IBM Tealeaf Customer Experience before 8.7.1.8847 FP10, 8.8 before 8.8.0.9049 FP9, 9.0.0 and 9.0.1 before 9.0.1.1117 FP5, 9.0.1A before 9.0.1.5108_9.0.1A FP5, 9.0.2 before 9.0.2.1223 FP3, and 9.0.2A before 9.0.2.5224_9.0.2A FP3 does not enforce password-length restrictions, which makes it easier for remote attackers to obtain access via a brute-force attack.Show less