The change-email form has no CSRF token and the session cookie is not SameSite - a cross-site page can set your email to attacker@evil.com. Separately, the signature preview reads location.hash into innerHTML. Fire it and prove execution by having your payload call back — capture the flag with /exam/profile#<img src=x onerror="fetch('/exam/api/solve/dom').then(r=>r.text()).then(alert)">.