Vulnerabilities > Weak Password Recovery Mechanism for Forgotten Password
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2021-01-19 | CVE-2021-25323 | Weak Password Recovery Mechanism for Forgotten Password vulnerability in Misp 2.4.136 The default setting of MISP 2.4.136 did not enable the requirements (aka require_password_confirmation) to provide the previous password when changing a password. | 9.1 |
2021-01-04 | CVE-2020-5361 | Weak Password Recovery Mechanism for Forgotten Password vulnerability in Dell CPG Bios Select Dell Client Commercial and Consumer platforms support a BIOS password reset capability that is designed to assist authorized customers who forget their passwords. | 7.6 |
2020-12-24 | CVE-2020-28186 | Weak Password Recovery Mechanism for Forgotten Password vulnerability in Terra-Master TOS Email Injection in TerraMaster TOS <= 4.2.06 allows remote unauthenticated attackers to abuse the forget password functionality and achieve account takeover. | 7.3 |
2020-12-04 | CVE-2020-27408 | Weak Password Recovery Mechanism for Forgotten Password vulnerability in Os4Ed Opensis 7.3/7.6 OpenSIS Community Edition through 7.6 is affected by incorrect access controls for the file ResetUserInfo.php that allow an unauthenticated attacker to change the password of arbitrary users. | 7.5 |
2020-10-27 | CVE-2020-27179 | Weak Password Recovery Mechanism for Forgotten Password vulnerability in Konzept-Ix Publixone konzept-ix publiXone before 2020.015 allows attackers to take over arbitrary user accounts by crafting password-reset tokens. | 9.8 |
2020-09-17 | CVE-2020-25728 | Weak Password Recovery Mechanism for Forgotten Password vulnerability in Alfresco Reset Password The Reset Password add-on before 1.2.0 for Alfresco has a broken algorithm (involving an increment) that allows a malicious user to change any user's account password include the admin account. | 8.8 |
2020-09-03 | CVE-2020-25105 | Weak Password Recovery Mechanism for Forgotten Password vulnerability in Eramba 2.19.3/2.8.1 eramba c2.8.1 and Enterprise before e2.19.3 has a weak password recovery token (createHash has only a million possibilities). | 9.8 |
2020-06-24 | CVE-2020-14016 | Weak Password Recovery Mechanism for Forgotten Password vulnerability in Naviwebs Navigate CMS 2.9 An issue was discovered in Navigate CMS 2.9 r1433. | 5.3 |
2020-06-24 | CVE-2020-14015 | Weak Password Recovery Mechanism for Forgotten Password vulnerability in Naviwebs Navigate CMS 2.9 An issue was discovered in Navigate CMS 2.9 r1433. | 7.5 |
2020-03-23 | CVE-2019-6560 | Weak Password Recovery Mechanism for Forgotten Password vulnerability in Auto-Maskin products In Auto-Maskin RP210E Versions 3.7 and prior, DCU210E Versions 3.7 and prior and Marine Observer Pro (Android App), the software contains a mechanism for users to recover or change their passwords without knowing the original password, but the mechanism is weak. | 9.1 |