The serviceURL parameter is currently vulnerable to XSS attacks. If you click HERE then after logging in you will see your CASI node session cookies being displayed in the alert box.
Note: The CASI tokens are httpOnly hence they are immune to XSS attacks.