[rwth-security] lastpass: bypassing do_popupregister() leaks credentials from previous site