Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Question2Answer 1.8.8 Session Fixation via Forgot-Password Flow
Vulnerability Description
Question2Answer through 1.8.8 contains a session invalidation vulnerability that allows attackers with a previously obtained remember-me cookie to retain authenticated access by exploiting the forgot-password reset flow's failure to clear the sessioncode field in qa-include/app/users-edit.php. While the normal password-change flow in qa-include/pages/account.php explicitly clears the sessioncode to invalidate persistent qa_session cookies, the forgot-password handler qa_finish_reset_user() omits this step, allowing any valid persistent cookie issued before the reset to continue authenticating the account after the password reset completes.
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Vulnerability Type
不充分的会话过期机制
Vulnerability Title
q2a question2answer 会话机制问题漏洞
Vulnerability Description
q2a question2answer是q2a组织的一款问答平台软件。 q2a question2answer 1.8.8及之前版本存在会话机制问题漏洞,该漏洞源于忘记密码重置流程未能清除qa-include/app/users-edit.php中的sessioncode字段,导致攻击者利用此前获得的remember-me cookie在密码重置后保留已验证的访问权限。
CVSS Information
N/A
Vulnerability Type
N/A