Description
Bypass of Password Confirmation - Unverified Password Change (authenticated change without current password)
An authenticated user is allowed to change their account password without supplying the current password or any additional verification.
Recommendation
Update the flowise-ui package to the latest compatible version. Followings are version details:
- Affected version(s): < 3.0.10
- Patched version(s): 3.0.10
References
Could your website be exposed too?
SmartScanner can check your website for Flowise does not Prevent Bypass of Password Confirmation - Unverified Password Change and gives you actionable findings to investigate.
Start a free scanRelated Issues
- Flowise doesn't Prevent Bypass of Password Confirmation through Unverified Email Change (credentials) - Vulnerability
- @udecode/plate-link does not sanitize URLs to prevent use of the `javascript:` scheme - CVE-2023-34245
- vue-i18n's escapeParameterHtml does not prevent DOM-based XSS through its tag attributes - @intlify/core - CVE-2025-53892
- vue-i18n's escapeParameterHtml does not prevent DOM-based XSS through its tag attributes - @intlify/core-base - CVE-2025-53892


