Comment 11 for bug 1575913

Revision history for this message
Travis McPeak (travis-mcpeak) wrote :

I agree with Jeremy. Worst case impact based on description seems like creating a lot of key-pairs and annoying the user.

That being said, it's valid CSRF and should be fixed, albeit in the open.