Prototype (prototypejs) framework contains a flaw that may allow a malicious user to obtain user data. The framework is using JSON, without an associated protection scheme. This way, an attacker may be able to inject other javascript code, and capture the data destined to the user.