Vulnerable Systems:
* Drupal 4.7.x before Drupal 4.7.8
* Drupal 5.x before Drupal 5.3
The publication status of comments is not passed during the hook_comments API operation, causing various modules that rely on the publication status (such as Organic groups, or Subscriptions) to mail out unpublished comments.
Vendor Status:
Drupal issued an update for this vulnerability