The cross-site scripting vulnerability could have allowed trivial account takeover.
Source: Threadpost