Comment Re:This issue is way overblown. FUD (Score 3, Informative) 225
Nope, it affects https as well. Furthermore, it does not require remote web management since the attack can be carried out via CSRF.
If in any problem you find yourself doing an immense amount of work, the answer can be obtained by simple inspection.