Vulnerabilities > Weak Password Recovery Mechanism for Forgotten Password

DATE CVE VULNERABILITY TITLE RISK
2018-04-13 CVE-2018-10081 Weak Password Recovery Mechanism for Forgotten Password vulnerability in Cmsmadesimple CMS Made Simple
CMS Made Simple (CMSMS) through 2.2.6 contains an admin password reset vulnerability because data values are improperly compared, as demonstrated by a hash beginning with the "0e" substring.
network
low complexity
cmsmadesimple CWE-640
critical
9.8
2018-04-12 CVE-2014-6412 Weak Password Recovery Mechanism for Forgotten Password vulnerability in Wordpress
WordPress before 4.4 makes it easier for remote attackers to predict password-recovery tokens via a brute-force approach.
network
high complexity
wordpress CWE-640
8.1
2018-03-14 CVE-2018-0787 Weak Password Recovery Mechanism for Forgotten Password vulnerability in Microsoft Asp.Net Core 1.0/1.1/2.0
ASP.NET Core 1.0.
network
low complexity
microsoft CWE-640
8.8
2018-02-21 CVE-2017-12161 Weak Password Recovery Mechanism for Forgotten Password vulnerability in Keycloak
It was found that keycloak before 3.4.2 final would permit misuse of a client-side /etc/hosts entry to spoof a URL in a password reset request.
network
low complexity
keycloak CWE-640
8.8
2018-01-31 CVE-2017-8916 Weak Password Recovery Mechanism for Forgotten Password vulnerability in Cisecurity Cis-Cat PRO Dashboard
In Center for Internet Security CIS-CAT Pro Dashboard before 1.0.4, an authenticated user is able to change an administrative user's e-mail address and send a forgot password email to themselves, thereby gaining administrative access.
local
low complexity
cisecurity CWE-640
7.8
2018-01-30 CVE-2017-1000141 Weak Password Recovery Mechanism for Forgotten Password vulnerability in Mahara
An issue was discovered in Mahara before 18.10.0.
network
low complexity
mahara CWE-640
6.5
2018-01-02 CVE-2017-17097 Weak Password Recovery Mechanism for Forgotten Password vulnerability in Gps-Server GPS Tracking Software
gps-server.net GPS Tracking Software (self hosted) 2.x has a password reset procedure that immediately resets passwords upon an unauthenticated request, and then sends e-mail with a predictable (date-based) password to the admin, which makes it easier for remote attackers to obtain access by predicting this new password.
network
low complexity
gps-server CWE-640
critical
9.8
2017-10-24 CVE-2015-5172 Weak Password Recovery Mechanism for Forgotten Password vulnerability in multiple products
Cloud Foundry Runtime cf-release before 216, UAA before 2.5.2, and Pivotal Cloud Foundry (PCF) Elastic Runtime before 1.7.0 allow attackers to have unspecified impact by leveraging failure to expire password reset links.
network
low complexity
pivotal-software cloudfoundry CWE-640
critical
9.8
2017-10-17 CVE-2017-14005 Weak Password Recovery Mechanism for Forgotten Password vulnerability in Prominent Multiflex M10A Controller Firmware
An Unverified Password Change issue was discovered in ProMinent MultiFLEX M10a Controller web interface.
network
low complexity
prominent CWE-640
8.8
2017-09-11 CVE-2015-4689 Weak Password Recovery Mechanism for Forgotten Password vulnerability in Ellucian Banner Student
Ellucian (formerly SunGard) Banner Student 8.5.1.2 through 8.7 allows remote attackers to reset arbitrary passwords via unspecified vectors, aka "Weak Password Reset."
network
low complexity
ellucian CWE-640
critical
9.8