ParentFull threadandfarm·I don't think it's actually any more powerful in that regard than, say, <iframe> tags. If your application lets users perform destructive actions with a GET request, you were already vulnerable.View on HN