Does this mean that currently this issue is still exploitable even with domain lockdown? Or do you

Does this mean that currently this issue is still exploitable even with domain lockdown? Or do you mean that users that sign up from other providers are vulnerable, and not that that makes us (CF users) vulnerable?
Was this page helpful?