The logout option within MFA did not include the necessary token to avoid the risk of users inadvertently being logged out via CSRF.
{ "cpes": [ "cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:*" ], "severity": "High" }