ParentFull threadmemoryfault·I disagree with that. It's a get request that is changing state server-side. That is a dead giveaway for a CSRF vulnerability.View on HN