An authenticated user attempting to change their password could do so without using the current password.
SEL·CWE-620·Published 2025-05-12