This module doesn't check to see whether the user intended to load the URL when a vote is cast, leaving the module open to a CSRF attack, the scope of which is limited to unwittingly casting votes. Adding a token to the end of the URL should suffice.

Comments

greggles’s picture

subscribe

joshk’s picture

Status: Active » Closed (fixed)

handled by dmitrig