CVE-2026-64829 | q2a Question2Answer up to 1.8.8 Forgot Password users-edit.php qa_finish_reset_user sessioncode session expiration (ID 1017)

SecurityVulns

A vulnerability, which was classified as problematic, was found in q2a Question2Answer up to 1.8.8. This vulnerability affects the function qa_finish_reset_user of the file qa-include/app/users-edit.php of the component Forgot Password. The manipulation of the argument sessioncode results in session expiration.

This vulnerability is known as CVE-2026-64829. It is possible to launch the attack remotely. No exploit is available.

Applying a patch is advised to resolve this issue.VulDB Recent EntriesRead More