XOOPS Permissions Privileges and Access Controls Vulnerability - CVE-2009-4851 - Vulnerability Database

XOOPS Permissions Privileges and Access Controls Vulnerability - CVE-2009-4851

Medium
Reference: CVE-2009-4851
Title: XOOPS Permissions Privileges and Access Controls Vulnerability
Overview:

The activation resend function in the Profiles module in XOOPS before 2.4.1 sends activation codes in response to arbitrary activation requests which allows remote attackers to bypass administrative approval via a request involving activate.php.