CyberRota Analysis
AI-GeneratedThe vulnerability allows regular users to bypass the admin approval process by using a confirmation hash that can be obtained through a public action, effectively enabling unauthorized account activation. This could lead to unauthorized access and potential exploitation of user accounts. Organizations utilizing this extension should prioritize remediation to prevent potential account takeover and unauthorized access incidents.
Original NVD Description
The extension fails to require the dedicated admin confirmation token when processing an admin-approval request, so a regular user confirmation hash, obtainable by any visitor through the public resend-confirmation action, is sufficient to self-approve a pending account awaiting admin approval.