Comment 3 for bug 678401

Revision history for this message
William Grant (wgrant) wrote :

All known Referer spoofing vulnerabilities are long-fixed, and there are far worse old browser holes that could be exploited.

However, it's still fragile since lots of people block the header. CSRF tokens should be added.