Identity Management / New Password Only Written Once (Password Reset)
Web and API
Description
If the password for an account is reset, the new password only needs to be typed once.
Risk
If a new password is set without a second confirmation, the risk of a typing error is increased. This could result in a user locking themselves out of their account.
Solution
To confirm the new password, the new password to be set should be entered twice.