Profile Module Manager - Moderately Critical - Cross Site Request Forgery
Project
Date
Severity
Moderately Critical
Affected versions
<7.x-2.2
The bundle enable menu callback performs state changing actions in response to a simple GET request without validating a token, so a forged link can enable modules and log every other user out of the site on behalf of an authenticated bundle manager.