VulnerabilityModified
CVE-2009-4851
The activation resend function in the Profiles module in XOOPS before 2.4.1 sends activation codes in response to arbitrary activation requests, which allows remote attackers to bypass administrative approval via a request involving activate.php.
MEDIUM 5.0EPSS 1.21%
Does this matter?
Lower severity and a low EPSS score (1.21%). Track it; it rarely justifies an emergency change on its own.
Description
The activation resend function in the Profiles module in XOOPS before 2.4.1 sends activation codes in response to arbitrary activation requests, which allows remote attackers to bypass administrative approval via a request involving activate.php.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
- EPSS
- 1.21% probability · 67th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- xoops/xoops
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/37274Vendor Advisory
- http://www.vupen.com/english/advisories/2009/3256Vendor Advisory
- http://www.xoops.org/modules/newbb/viewtopic.php?post_id=319132
- http://www.xoops.org/modules/news/article.php?storyid=5096Patch
- http://secunia.com/advisories/37274Vendor Advisory
- http://www.vupen.com/english/advisories/2009/3256Vendor Advisory
- http://www.xoops.org/modules/newbb/viewtopic.php?post_id=319132
- http://www.xoops.org/modules/news/article.php?storyid=5096Patch
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.