This is probably not the answer you are looking for, but this is just a more security wise practice.
Password should be One Way Hashed, when the user ask for a new Password, you should send him a temporary random password that he will change on next login.