Board Thread:Support Requests - Getting Technical/@comment-25295528-20161017152024/@comment-24473195-20161018101627

Monkeypolice188 wrote: I thought it'd be relatively simple; java script loading a template. My rail modules js does the same thing, albeit with (obviously) a module string before the template. I think you misunderstood Saftzie's comment. You can actually do what you want (if you understand Javascript) because the person who designed the script left it wide open  to all sort of abuses through that security hole.

Assuming that you're talking about addrailmodule in dev.wiki, it actually employs a very simple alternative to load content from a template, and doesn't (probably) have the same issue.

Saftzie: Oddly enough, Staff was the last one to make edits to that script (probably auto-approving those edits), and they likely missed that security hole.