MEDIUM
The activation resend function in the Profiles module in XOOPS before 2.4.1 sends activation codes in response to arbitrary activation requests, which allows remote attackers to bypass administrative approval via a request involving activate.php
Published May 7, 2010
5.0
MEDIUMCVSS 2.0
EPSS 1.21%
Description
The activation resend function in the Profiles module in XOOPS before 2.4.1 sends activation codes in response to arbitrary activation requests, which allows remote attackers to bypass administrative approval via a request involving activate.php.
Affected products
No data.
OR
- ≤ 2.4.0
- 1.0
- 1.0_rc1
- 1.0_rc3
- 1.0_rc3.0.5
- 1.3.5
- 1.3.6
- 1.3.7
- 1.3.8
- 1.3.9
- 1.3.10
- 2.0.0
- 2.0.0_rc1
- 2.0.0_rc2
- 2.0.0_rc3
- 2.0.1
- 2.0.2
- 2.0.3
- 2.0.4
- 2.0.5.1
- 2.0.5.2
- 2.0.5_rc
- 2.0.6
- 2.0.7
- 2.0.7.1
- 2.0.7.2
- 2.0.7.3
- 2.0.9
- 2.0.9.2
- 2.0.9.3
- 2.0.10
- 2.0.10_rc
- 2.0.11
- 2.0.12
- 2.0.12a
- 2.0.13
- 2.0.13.1
- 2.0.13.2
- 2.0.14
- 2.0.14-rc1
- 2.0.15
- 2.0.16
- 2.0.17
- 2.0.17.1
- 2.0.18
- 2.0.18.1
- 2.3.0
- 2.3.0_alpha_3
- 2.3.0_alpha1
- 2.3.0_alpha2
- 2.3.0_beta
- 2.3.0_rc
- 2.3.0_rc2
- 2.3.0_rc3
- 2.3.1
- 2.3.1_rc
- 2.3.2a
- 2.3.2b
- 2.3.3
- 2.4.0_beta_1
- 2.4.0_beta_2
- 2.4.0_rc
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (4)
- http://secunia.com/advisories/37274 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://www.vupen.com/english/advisories/2009/3256 vdb-entryx_refsource_VUPENVendor Advisory
- http://www.xoops.org/modules/newbb/viewtopic.php?post_id=319132 x_refsource_MISC
- http://www.xoops.org/modules/news/article.php?storyid=5096 x_refsource_CONFIRMPatch
| Link | Providers | Tags |
|---|---|---|
| http://secunia.com/advisories/37274 | third-party-advisoryx_refsource_SECUNIAVendor Advisory | |
| http://www.vupen.com/english/advisories/2009/3256 | vdb-entryx_refsource_VUPENVendor Advisory | |
| http://www.xoops.org/modules/newbb/viewtopic.php?post_id=319132 | x_refsource_MISC | |
| http://www.xoops.org/modules/news/article.php?storyid=5096 | x_refsource_CONFIRMPatch |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published May 7, 2010
Updated Sep 16, 2024
Reserved May 7, 2010
Link CVE-2009-4851
CISA Vulnrichment
Updated n/a