CSRF
Easy · CSRF

Change Email from Another Site

You are signed in to ClientPortal. Its email-change endpoint trusts the session cookie but has no anti-CSRF token. A separate attacker page can submit the same form without being able to read the response.

Objective

Use the built-in attacker-site launcher to change Maya's email, then return to ClientPortal and verify the changed account state.

Target

ClientPortal / Request Tester

Launch target

Submit flag