Csrf vulnerability

Closes #3454892

Merge request reports

Loading