Description qa-include/qa-install.php in Question2Answer before 1.7.5 allows remote attackers to create multiple user accounts. Remediation References CVE-2017-12775 Related Vulnerabilities MySQL CVE-2018-2784 Vulnerability (CVE-2018-2784) Magento Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2019-8130) Ruby Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Vulnerability (CVE-2008-1891) Oracle Application Server CVE-2006-0285 Vulnerability (CVE-2006-0285) WordPress Permissions, Privileges, and Access Controls Vulnerability (CVE-2008-3747) Severity High Classification CVE-2017-12775 CWE-20 CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N Tags Missing Update Known Vulnerabilities