There is a xsrf bug in this hack, and i can set thanks or groans by <script src="post_thanks_add.php...blablabla..."></script> on my domain if user cookies was set for another site/domain. And we can use cookies from another site with this hack.
It's enough to give link to this page to use this bug.
May be the best solution is to use additional http X-header for ajax-requests.
|