Full threadl0b0·Nice find! As for the provider, since they missed this extremely basic step (don't trust the client!!) I would expect they have many more undiscovered vulnerabilities.View on HN