... email in the Thunderbird product because scripting is disabled when reading mail, but are ... not consider the use of document.domain for cross-origin protections. If pages on different ... This can allow an attacker to perform Cross-Site Request Forgery (CSRF) attacks. References ...