> For the complete documentation index, see [llms.txt](https://wiki.smhuda.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://wiki.smhuda.com/vulnerability-wiki/application-level/authentication/lack-of-password-confirmation.md).

# Lack of Password Confirmation

### Severity:&#x20;

<mark style="color:green;">**Low**</mark>

### How to test:

1. A password confirmation should be generated and current password requested for atleast the following items:
   1. Change password
   2. Change primary email
   3. Change 2FA
   4. Delete Account
   5. Add Account
   6. Change membership etc.
