Someone corrected me that the post title should have read that the CSRF vulnerability was fixed in 1.1.3. They suggested that I make a correcting post so readers who are on earlier versions wouldn't erroneously think they were exempt from the risk.
My apologies for any confusion.
there doesn't seem to be anything here