The change password functionality in Bottomline Webseries...
Low severity
Unreviewed
Published
May 1, 2022
to the GitHub Advisory Database
•
Updated Jan 30, 2023
Description
Published by the National Vulnerability Database
Jan 11, 2005
Published to the GitHub Advisory Database
May 1, 2022
Last updated
Jan 30, 2023
The change password functionality in Bottomline Webseries Payment Application does not require the old password when users enter a new password, which could allow remote authenticated users to change other users' passwords.
References