Full threadcapableweb·Interesting that something basic like a CSRF vulnerability have existed for so long in the project. I wonder what other "low-hanging fruit" vulnerabilities they have nested in there if they don't something like that right.View on HN