CVE-2017-12775

HIGH

Question2answer < 1.7.4 - Improper Input Validation

Title source: rule
STIX 2.1

Description

qa-include/qa-install.php in Question2Answer before 1.7.5 allows remote attackers to create multiple user accounts.

References (2)

Core 2

Scores

CVSS v3 7.5
EPSS 0.0029
EPSS Percentile 52.6%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Details

CWE
CWE-20
Status published
Products (1)
question2answer/question2answer < 1.7.4
Published Aug 29, 2017
Tracked Since Feb 18, 2026