Your right when you say that sessions would be stronger overall. The password(in md5) will then no longer be present in your cookies. But still its vulnerable.
Still some could steal your cookie by an XSS attack. And use your session for the remaining time.
A some what more of an security issue. Is the way you can change your password in profile.php.
Last week I logged into my forum as admin at my brothers pc. After a short break a came back online at a different pc. Noticed that I no longer could log in as admin. And that my password was changed. Just before I wanted to change it directly in MySQL . My brother said he had changed the pass for the fun.
So really nothing to worry about.
The moral of this story is. That punbb should ask for your old password when changing to a new password.
I?m sorry if this is already done . Because at that time I was running punbb 1.2 .
Whoops just noticed it that it allready has been fixed.