Vulnerabilities > Weak Password Recovery Mechanism for Forgotten Password

DATE CVE VULNERABILITY TITLE RISK
2020-09-03 CVE-2020-25105 Weak Password Recovery Mechanism for Forgotten Password vulnerability in Eramba 2.19.3/2.8.1
eramba c2.8.1 and Enterprise before e2.19.3 has a weak password recovery token (createHash has only a million possibilities).
network
low complexity
eramba CWE-640
5.0
2020-07-01 CVE-2020-5899 Weak Password Recovery Mechanism for Forgotten Password vulnerability in F5 Nginx Controller
In NGINX Controller 3.0.0-3.4.0, recovery code required to change a user's password is transmitted and stored in the database in plain text, which allows an attacker who can intercept the database connection or have read access to the database, to request a password reset using the email address of another registered user then retrieve the recovery code.
local
low complexity
f5 CWE-640
4.6
2020-06-24 CVE-2020-14016 Weak Password Recovery Mechanism for Forgotten Password vulnerability in Naviwebs Navigate CMS 2.9
An issue was discovered in Navigate CMS 2.9 r1433.
network
low complexity
naviwebs CWE-640
5.0
2020-06-24 CVE-2020-14015 Weak Password Recovery Mechanism for Forgotten Password vulnerability in Naviwebs Navigate CMS 2.9
An issue was discovered in Navigate CMS 2.9 r1433.
network
low complexity
naviwebs CWE-640
5.0
2020-03-23 CVE-2019-6560 Weak Password Recovery Mechanism for Forgotten Password vulnerability in Auto-Maskin products
In Auto-Maskin RP210E Versions 3.7 and prior, DCU210E Versions 3.7 and prior and Marine Observer Pro (Android App), the software contains a mechanism for users to recover or change their passwords without knowing the original password, but the mechanism is weak.
network
low complexity
auto-maskin CWE-640
6.4
2020-02-04 CVE-2012-5686 Weak Password Recovery Mechanism for Forgotten Password vulnerability in Zpanelcp Zpanel 10.0.1
ZPanel 10.0.1 has insufficient entropy for its password reset process.
network
low complexity
zpanelcp CWE-640
7.5
2020-02-04 CVE-2012-5618 Weak Password Recovery Mechanism for Forgotten Password vulnerability in Ushahidi
Ushahidi before 2.6.1 has insufficient entropy for forgot-password tokens.
network
low complexity
ushahidi CWE-640
5.0
2020-01-23 CVE-2020-7245 Weak Password Recovery Mechanism for Forgotten Password vulnerability in Ctfd
Incorrect username validation in the registration process of CTFd v2.0.0 - v2.2.2 allows an attacker to take over an arbitrary account if the username is known and emails are enabled on the CTFd instance.
network
ctfd CWE-640
6.8
2020-01-15 CVE-2009-5025 Weak Password Recovery Mechanism for Forgotten Password vulnerability in Pyforum Project Pyforum 1.0.3
A backdoor (aka BMSA-2009-07) was found in PyForum v1.0.3 where an attacker who knows a valid user email could force a password reset on behalf of that user.
network
low complexity
pyforum-project CWE-640
5.0
2020-01-05 CVE-2019-20004 Weak Password Recovery Mechanism for Forgotten Password vulnerability in Intelbras IWR 3000N Firmware 1.8.7
An issue was discovered on Intelbras IWR 3000N 1.8.7 devices.
network
low complexity
intelbras CWE-640
8.8