Cross-Site API Key Revoke
API-key revocation is protected only by the user's session cookie. The endpoint does not require a token and does not reject requests whose Origin/Referer belongs to another site.
Objective
Revoke the primary API key from the attacker site and use ClientPortal's request evidence to confirm the action came cross-site.