Project

General

Profile

Actions

Defect #13022

closed

Image pointing towards /logout signs out user

Added by Anonymous over 11 years ago. Updated over 11 years ago.

Status:
Closed
Priority:
Normal
Category:
Security
Target version:
Start date:
Due date:
% Done:

0%

Estimated time:
Resolution:
Fixed
Affected version:

Description

Creating an image with the source url /logout will automatically sign out any user.

Code

!/logout!

Test case (This will sign you out!)
See issue #13021

This can be annoying and should be prevented by only allowing POST request with a valid CSRF token in the AccountController.logout method (source:trunk/app/controllers/account_controller.rb).


Related issues

Has duplicate Redmine - Defect #13069: XSS with imagesClosed

Actions
Actions

Also available in: Atom PDF