An independent security researcher, Sow Ching Shiong, discovered a serious password reset vulnerability in Facebook that allows hackers to change passwords on Facebook accounts.
Normally, a user who wishes to change their password must enter their current password and the new password twice to prevent unauthorized persons from changing the password without the user's knowledge.
However, the researcher found that a hacker could change the user's password without knowing the user's current password. How? Very simply, from the url "https://www.facebook.com/hacked", which automatically redirects to the account recovery page.
From this page, an attacker can simply request a new password and confirm it (i.e. type the new password they chose twice), without needing to know any other information, according to ehackingnews.
Facebook's security team fixed the vulnerability after it was reported by the security researcher, and Sow Ching Shiong has been added to the list of Facebook Whitehats (https://www.facebook.com/whitehat).

