http://en.wikipedia.org/wiki/Cross-site_request_forgery
You may want to set up a transfer confirm email, or you may want to add a CSRF hash to your form data so that it can't be spoofed and the server is checking that each submission is in fact from the right server.
This bug will circumvent 2FA. So I probably won't stay logged in and clicking external links until this problem is fixed.
Just my two cents.
Glad to see that its disabled right now, guess you are looking into it? I saw some poor souls getting scammed on reddit
Ukyo, are you starting to see my point yet?
.b