Description
Cross-Site Request Forgery (CSRF) vulnerability in Drupal Automated Logout allows Cross Site Request Forgery.This issue affects Automated Logout: from 0.0.0 before 1.7.0, from 2.0.0 before 2.0.2.
Problem types
CWE-352 Cross-Site Request Forgery (CSRF)
Product status
0.0.0 (semver) before 1.7.0
2.0.0 (semver) before 2.0.2
Credits
Pierre Rudloff (prudloff)
Ajit Shinde (ajits)
Jakob P (japerry)
Gareth Alexander (the_g_bomb)
Greg Knaddison (greggles)
Juraj Nemec (poker10)
Jess (xjm)
References
www.drupal.org/sa-contrib-2026-030