qa_finish_reset_user of the file qa-include/app/users-edit.php of the component Forgot Password. The manipulation of the argument sessioncode results in session expiration.This vulnerability is known as CVE-2026-64829. It is possible to launch the attack remotely. No exploit is available.
Applying a patch is advised to resolve this issue.
SOCIAL SHARE CARD GENERATOR