Absolutely amazing. A friend and I just tested this and it's true. It makes me think this is a little more than the "rogue employee" story they're peddling.
Seems like a huge liability. They are still disseminating these messages under the identities of major public figures, 8 hours after they became aware of it.
For example try this with JS disabled vs enabled (404): https://mobile.twitter.com/JoeBiden/status/12835123178466590...