Unsafe State-Changing GET
ClientPortal has a legacy endpoint that disables security alerts using GET. Because a normal cross-site link can issue a top-level GET, an external site can trigger the change.
Objective
Use the attacker page's link to disable security alerts, then verify the state change in ClientPortal.