user · is_admin: FalseAAUrBgQQAAcRKw8AClFIMkcWExoIQSURFw5SThe forwarding form has no CSRF token and the session cookie is not SameSite - a cross-site request can set it to attacker@evil.com. The signature preview reads location.hash into innerHTML: prove execution via /settings#<img src=x onerror="fetch('/exam3/api/solve/dom')">. The "encrypted" backup key is just base64(XOR) with a key hiding in config.bak - reverse it.