CVE-2017-12775: QUESTION2ANSWER

High severity, CVSS 7.5. EPSS: 1.6% chance of exploitation in the next 30 days.

qa-include/qa-install.php in Question2Answer before 1.7.5 allows remote attackers to create multiple user accounts.

Affected products

Published 2017-08-29. Last modified 2026-06-17.