Details
-
Feature Request
-
Status: Defined (View Workflow)
-
Major
-
Resolution: Unresolved
-
SaaS, 2.9.1 GA
-
None
Description
The password update form on the developer portal doesn't require entering the previous password thus representing a vulnerability threat.
A pending session enable a malicious user to change the credentials of an account without any oblstacle.