We have tested the 'Report This Post' and there is no floodcheck.
The user who has threatened us has already been banned but we suspect he will try to get a new user name. What alerted us to this problem is that we had a user awaiting moderation seemingly testing the 'Report This Post' function so we know that someone doesn't even have to be an approved user to launch such an attack (another problem that needs to be addressed). But whether awaiting moderation or not we need to protect ourselves from possible attacks from this vulnerability.
|