ClientPortal
Account · Security · Billing

Account email

The POST endpoint trusts the session cookie and does not require an anti-CSRF token.

CURRENT ACCOUNT STATE
maya@example.test
Lab session not started

Test workflow

  1. Establish the victim session. This simulates Maya already being signed in to ClientPortal.
  2. Open the attacker site in a new tab. Trigger its single forged request.
  3. Return here and verify account state. If the server accepted the cross-site request, the value above changes and the proof appears.
1. Start victim session