CWE-640
317 CVEs • Abstraction: Base • Likelihood of Exploit: High
Weak Password Recovery Mechanism for Forgotten Password
The product contains a mechanism for users to recover or change their passwords without knowing the original password, but the mechanism is weak.
CVEs (317)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
An authenticated standard user could reset the password of the admin by altering form data. Affects kanboard before 1.0.46. |
An authenticated standard user could reset the password of other users (including the admin) by altering form data. Affects kanboard before 1.0.46. |
1Microsoft 1Azure Active Directory Connect May 13, 2026 Jun 29, 2017 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 Azure AD Connect Password writeback, if misconfigured during enablement, allows an attacker to reset passwords and gain unauthorized access to arbitrary on-premises AD privileged user accounts aka "Azure AD Connect Eleva...Show more |
QNAP QTS before 4.2.6 build 20170517 has a flaw in the change password function. |
register.ghp in EFS Software Easy Chat Server versions 2.0 to 3.1 allows remote attackers to reset arbitrary passwords via a crafted POST request to registresult.htm. |
A weak password recovery vulnerability in Fortinet FortiPortal versions 4.0.0 and below allows attacker to carry out information disclosure via the Forgotten Password feature. |
2Cloudfoundry Pivotal Software3Cf Release Cloud Foundry Elastic RuntimeCloud Foundry UaaMay 13, 2026 May 25, 2017 N/A· v4 3.7 LOW· v3 4.3 MEDIUM· v2 With Cloud Foundry Runtime cf-release versions v208 or earlier, UAA Standalone versions 2.2.5 or earlier and Pivotal Cloud Foundry Runtime 1.4.5 or earlier, old Password Reset Links are not expired after the user changes...Show more |
WordPress through 4.7.4 relies on the Host HTTP header for a password-reset e-mail message, which makes it easier for remote attackers to reset arbitrary passwords by making a crafted wp-login.php?action=lostpassword req...Show more |
Craft CMS before 2.6.2976 does not prevent modification of the URL in a forgot-password email message. |
MantisBT through 2.3.0 allows arbitrary password reset and unauthenticated admin access via an empty confirm_hash value to verify.php. |
An exploitable Cleartext Transmission of Password vulnerability exists in the Web Application functionality of Moxa AWK-3131A Wireless Access Point running firmware 1.1. The Change Password functionality of the Web Appli...Show more |
EMC Documentum eRoom version 7.4.4, EMC Documentum eRoom version 7.4.4 SP1, EMC Documentum eRoom version prior to 7.4.5 P04, EMC Documentum eRoom version prior to 7.5.0 P01 includes an unverified password change vulnerab...Show more |
An issue was discovered in Pagekit CMS before 1.0.11. In this vulnerability the remote attacker is able to reset the registered user's password, when the debug toolbar is enabled. The password is successfully recovered u...Show more |
In Moodle 2.x and 3.x, web service tokens are not invalidated when the user password is changed or forced to be changed. |
1Bmc 1Remedy Action Request System May 6, 2026 Dec 21, 2016 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Remedy AR System Server in BMC Remedy 8.1 SP 2, 9.0, 9.0 SP 1, and 9.1 allows attackers to reset arbitrary passwords via a blank previous password. |
1Ibm 1Tealeaf Customer Experience May 6, 2026 Sep 26, 2016 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 The web portal in IBM Tealeaf Customer Experience before 8.7.1.8847 FP10, 8.8 before 8.8.0.9049 FP9, 9.0.0 and 9.0.1 before 9.0.1.1117 FP5, 9.0.1A before 9.0.1.5108_9.0.1A FP5, 9.0.2 before 9.0.2.1223 FP3, and 9.0.2A bef...Show more |
1Ibm 1Tealeaf Customer Experience May 6, 2026 Sep 26, 2016 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The web portal in IBM Tealeaf Customer Experience before 8.7.1.8847 FP10, 8.8 before 8.8.0.9049 FP9, 9.0.0 and 9.0.1 before 9.0.1.1117 FP5, 9.0.1A before 9.0.1.5108_9.0.1A FP5, 9.0.2 before 9.0.2.1223 FP3, and 9.0.2A bef...Show more |