This module enables users to remain logged in separately from session timeouts.
The module doesn't sufficiently check a user's disabled status when validating cookies.
This vulnerability is mitigated by the fact that an attacker must have an unexpired cookie from a previous successful login.
{
"constraint": "<1.8.0"
}
{
"constraint": ">=2.2.0 <2.2.2"
}