Open Atrium Notifications - Moderately Critical - Cross Site Request Forgery
Project
Date
Severity
Moderately Critical
Affected versions
<7.x-2.36
The Open Atrium Notifications remove callback deletes a notification subscription in response to a GET request but never validates the security token that its own remove links attach. An attacker can forge a request that makes an authenticated victim remove notification subscriptions without their consent.