answerdev/answer is an open-source knowledge-based community software. Answer prior to 1.0.6 is vulnerable to account takeover because the password reset link does not expire.
References
https://nvd.nist.gov/vuln/detail/CVE-2023-1976
https://github.co…