CVE-2026-64829 | q2a Question2Answer up to 1.8.8 Forgot Password users-edit.php qa_finish_reset_user sessioncode session expiration (ID 1017)
A vulnerability, which was classified as problematic, was found in q2a Question2Answer up to 1.8.8. This vulnerability affects the function qa_finish_reset_user of the file qa-include/app/users-edit.php of the component Forgot Password. The manipulation of the argument sessioncode results in session expiration.
This vulnerability is known as CVE-2026-64829. It is possible to launch the attack remotely. No exploit is available.
Applying a patch is advised to resolve this issue.VulDB Recent EntriesRead More