Yep, can confirm it too
But i think the bug is not exploitable, or almost impossible to exploit.
First you need a valid csrf token from a PM form, to create folders or see some success/error message.
Second, you can not access document.cookie in javascript for most browsers, as we set the HTTP-Only cookie option.
Will of course patch it when i have more time. (probably not before christmas)
Thanks for report!
Gizmore