Impact
The Automated Logout module for Drupal contains a Cross‑Site Request Forgery flaw (CWE‑352) that enables an attacker to trigger a logout action without the victim’s consent, thereby compromising session integrity and potentially leading to loss of user privileges and confusion.
Affected Systems
Drupal sites that have installed the Automated Logout module in any version prior to 1.7.0 or from 2.0.0 up to and including 2.0.1 are affected; these early releases contain the vulnerable logic and are listed as impacted in the advisory.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate severity while the EPSS score of less than 1 % suggests low likelihood of exploitation; the vulnerability is not listed in CISA’s KEV catalog. Based on the description, the attack vector requires an authenticated user who visits a malicious web page that submits a forged logout request, such as via a link or form on a third‑party site or a phishing page, causing an unexpected logout.
OpenCVE Enrichment