> For the complete documentation index, see [llms.txt](https://0xn3va.gitbook.io/application-security-handbook/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://0xn3va.gitbook.io/application-security-handbook/web-application/authentication/password-change.md).

# Password Change

## Overview

This page contains recommendations for the implementation of password change functionality.

## General

<div align="left"><img src="/files/QJuMWI21M60ZKzo0mFAN" alt=""></div>

* Request at least the following data during password change:
  * Old password.
  * New password.
  * Confirmation of the new password.
* Terminate all active sessions after changing a password.
* Implement the CSRF protection, see the [Vulnerability Mitigation: Cross-Site Request Forgery (CSRF)](/application-security-handbook/web-application/vulnerability-mitigation/cross-site-request-forgery-csrf.md) page.
* Log successful and failed password change attempts, see the [Logging and Monitoring](/application-security-handbook/web-application/logging-and-monitoring.md) page.
* Comply with requirements from the [Error and Exception Handling](/application-security-handbook/web-application/error-and-exception-handling.md) page.

<div align="left"><img src="/files/P0T6i9QsRZT0gGQKpPIC" alt=""></div>

* Limit the number of attempts to change the password for a certain period, see the [Vulnerability Mitigation: Brute-force](/application-security-handbook/web-application/vulnerability-mitigation/brute-force.md) page.
* Ask for a second factor when a user changes a password, if a multi-factor authentication is enabled.
