Open OnDemand before 1.5.7 and 1.6.x before 1.6.22 allows CSRF.
Go to Source of this post
Author Of this post:

By admin