CVE-2009-4851: Medium severity Xoops Xoops vulnerability
The activation resend function in the Profiles module in XOOPS before 2.4.1 sends activation codes in response to arbitrary activation requests, which allows remote attackers to bypass administrative approval via a request involving activate.php.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2009-4851?
CVE-2009-4851 is considered a high-severity vulnerability as it allows remote attackers to bypass administrative approval.
How do I fix CVE-2009-4851?
To mitigate CVE-2009-4851, upgrading to XOOPS version 2.4.1 or later is recommended.
What is the impact of CVE-2009-4851 on affected software?
CVE-2009-4851 can lead to unauthorized account activation by bypassing the intended administrative approval process.
Which versions of XOOPS are affected by CVE-2009-4851?
CVE-2009-4851 affects XOOPS versions prior to 2.4.1, including several earlier versions.
Is there a workaround for CVE-2009-4851?
A temporary workaround for CVE-2009-4851 could involve restricting access to the activation function until a suitable upgrade is applied.