Automated Logout - Moderately Critical - Cross-Site Request Forgery
Project
Date
Severity
Moderately Critical
Affected versions
<7.x-4.7
The Automated Logout module doesn't sufficiently protect its AJAX routes from cross-site request forgery (CSRF), allowing the logout route to be triggered without user interaction.