Impact
The vulnerability exists in Question2Answer through version 1.8.8. It permits an attacker who already holds a persistent remember‑me cookie to continue authenticating after triggering a password‑reset, because the forgot‑password flow fails to clear the sessioncode field. This results in a session fixation condition that allows the attacker to keep valid authority over the account without authenticating again, thereby compromising confidentiality and integrity for the affected user.
Affected Systems
The flaw affects installations of Question2Answer version 1.8.8 and earlier. All users that have the remember‑me feature enabled and whose accounts are subject to the password‑reset process are vulnerable. The issue is specific to the q2a:question2answer product.
Risk and Exploitability
The CVSS score of 9.1 indicates a high severity due to the ability of an attacker with a remembered session cookie to retain access after a password reset. The EPSS score of <1% signals a very low likelihood that this exploit will be observed in the wild. An attacker still needs to have earlier obtained a valid remember‑me cookie through phishing, credential stuffing, or a prior session hijack, which reduces the prevalence of this attack. The vulnerability is not yet listed in the CISA KEV catalog. Immediate mitigation is required to prevent long‑term account compromise.
OpenCVE Enrichment