The activation resend function in the Profiles module in XOOPS before 2.4.1 sends activation codes in response to arbitrary activation requests, which allows remote attackers to bypass administrative approval via a request involving activate.php.
| Software | From | Fixed in |
|---|---|---|
| xoops / xoops | 2.3.0_rc3 | 2.3.0_rc3.x |
| xoops / xoops | 1.3.6 | 1.3.6.x |
| xoops / xoops | 2.3.0_rc | 2.3.0_rc.x |
| xoops / xoops | 2.3.2b | 2.3.2b.x |
| xoops / xoops | 2.0.12 | 2.0.12.x |
| xoops / xoops | 2.3.0_alpha_3 | 2.3.0_alpha_3.x |
| xoops / xoops | 2.0.5.1 | 2.0.5.1.x |
| xoops / xoops | 2.0.2 | 2.0.2.x |
| xoops / xoops | 2.0.12a | 2.0.12a.x |
| xoops / xoops | 2.0.5.2 | 2.0.5.2.x |
| xoops / xoops | 2.0.16 | 2.0.16.x |
| xoops / xoops | 2.3.0_beta | 2.3.0_beta.x |
| xoops / xoops | 2.0.0_rc1 | 2.0.0_rc1.x |
| xoops / xoops | 2.0.13.1 | 2.0.13.1.x |
| xoops / xoops | 2.0.0_rc2 | 2.0.0_rc2.x |
| xoops / xoops | 2.0.7.3 | 2.0.7.3.x |
| xoops / xoops | 1.3.10 | 1.3.10.x |
| xoops / xoops | 2.0.15 | 2.0.15.x |
| xoops / xoops | 2.0.13 | 2.0.13.x |
| xoops / xoops | 2.3.2a | 2.3.2a.x |
| xoops / xoops | 2.4.0_beta_1 | 2.4.0_beta_1.x |
| xoops / xoops | 1.3.5 | 1.3.5.x |
| xoops / xoops | 1.0 | 1.0.x |
| xoops / xoops | 2.0.5_rc | 2.0.5_rc.x |
| xoops / xoops | 2.0.14-rc1 | 2.0.14-rc1.x |
| xoops / xoops | 2.3.0_alpha2 | 2.3.0_alpha2.x |
| xoops / xoops | 2.0.9.2 | 2.0.9.2.x |
| xoops / xoops | 2.0.7 | 2.0.7.x |
| xoops / xoops | 2.0.18.1 | 2.0.18.1.x |
| xoops / xoops | 2.0.3 | 2.0.3.x |
| xoops / xoops | 1.0_rc1 | 1.0_rc1.x |
| xoops / xoops | 2.0.13.2 | 2.0.13.2.x |
| xoops / xoops | 2.0.9 | 2.0.9.x |
| xoops / xoops | 2.0.4 | 2.0.4.x |
| xoops / xoops | 2.4.0_rc | 2.4.0_rc.x |
| xoops / xoops | 2.3.0 | 2.3.0.x |
| xoops / xoops | 1.3.9 | 1.3.9.x |
| xoops / xoops | 1.0_rc3.0.5 | 1.0_rc3.0.5.x |
| xoops / xoops | 2.0.14 | 2.0.14.x |
| xoops / xoops | 2.0.1 | 2.0.1.x |
| xoops / xoops | 2.0.10 | 2.0.10.x |
| xoops / xoops | 2.3.0_rc2 | 2.3.0_rc2.x |
| xoops / xoops | 2.0.0_rc3 | 2.0.0_rc3.x |
| xoops / xoops | 2.0.7.2 | 2.0.7.2.x |
| xoops / xoops | 2.0.7.1 | 2.0.7.1.x |
| xoops / xoops | 1.3.7 | 1.3.7.x |
| xoops / xoops | 2.0.0 | 2.0.0.x |
| xoops / xoops | 2.0.17 | 2.0.17.x |
| xoops / xoops | 2.0.11 | 2.0.11.x |
| xoops / xoops | 2.4.0_beta_2 | 2.4.0_beta_2.x |
| xoops / xoops | 1.0_rc3 | 1.0_rc3.x |
| xoops / xoops | - | 2.4.0.x |
| xoops / xoops | 2.3.1 | 2.3.1.x |
| xoops / xoops | 2.3.0_alpha1 | 2.3.0_alpha1.x |
| xoops / xoops | 2.0.17.1 | 2.0.17.1.x |
| xoops / xoops | 2.0.18 | 2.0.18.x |
| xoops / xoops | 2.0.10_rc | 2.0.10_rc.x |
| xoops / xoops | 2.3.1_rc | 2.3.1_rc.x |
| xoops / xoops | 2.0.9.3 | 2.0.9.3.x |
| xoops / xoops | 2.0.6 | 2.0.6.x |
| xoops / xoops | 2.3.3 | 2.3.3.x |
| xoops / xoops | 1.3.8 | 1.3.8.x |