@nebulon I mean the place where all users are listed.
There is a risk that the password change may become missused to gain unauthorized access to someone else account. All because the fact that the password change form doesn't ask for neither old password, or 2FA key (if it's enabled for the user).
The best example of that is visible in the online demo