Saltar al contenido principal

Configuración de cookies

Utilizamos cookies para asegurar las funcionalidades básicas del sitio web y para mejorar tu experiencia en línea. Puedes configurar y aceptar el uso de las cookies, y modificar tus opciones de consentimiento en cualquier momento.

Esenciales

Preferencias

Analíticas y estadísticas

Marketing

This proposal has been implemented

Change "change password" process to make user retype current password

Avatar: Antoine Billard Antoine Billard Finished

Is your feature request related to a problem? Please describe.
If a user has a session open, anyone can change their password without typing current password.

Describe the solution you'd like
In the change password request, either have the mandatory field 'current password' to avoid any identify theft

Describe alternatives you've considered
Change password via Mail link ?

Does this issue could impact on users private data?
Yes , if shared computers or opened sessions, their password can be changed.

Funded by
No funding available

Comentario

Confirmar

Por favor, inicia la sesión

La contraseña es demasiado corta.

Compartir