The bugs include a reflected cross-site scripting glitch and a cross-site request forgery vulnerability.
Source: Threadpost