Posted by Andrey Stoykov on Oct 28
# Exploit Title: Current Password not Required When Changing Password –
totaljsv5013
# Date: 10/2025
# Exploit Author: Andrey Stoykov
# Version: 5013
# Tested on: Debian 12
# Blog:
https://msecureltd.blogspot.com/2025/10/friday-fun-pentest-series-43-current.html
Current Password not Required When Changing Password:
Steps to Reproduce:
1. Login with user and click on profile icon
2. Select “Change Credentials”
3. The user would not be…
– Read More – Full Disclosure



