CWE-620: Unverified Password Change
BaseDraft
When setting a new password for a user, the product does not require knowledge of the original password, or using another form of authentication.
View on MITREBack to CWE Lookup
Extended Description
This could be used by an attacker to change passwords for another user, thus gaining the privileges associated with that user.
Technical Details
- Structure
- Simple
Applicable To
Not Language-Specific