From Recon to Account Takeover: 

Discovering a Hidden Password Change Flaw