The change password functionality in Bottomline Webseries Payment Application does not require the old password when users enter a new password, which could allow remote authenticated users to change other users passwords.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Webseries_payment_application | Bottomline | 4.0 (including) | 4.0 (including) |