Settings

Email: you@ratdesk.local
Display name: You
Mail forwarding: (none)
Role: user · is_admin: False

Mail forwarding

Signature preview (client-side)

Signature: Sent from RatDesk
Edit & server-side preview signature

Backup key export

Your encrypted backup key: AAUrBgQQAAcRKw8AClFIMkcWExoIQSURFw5S

The forwarding form has no CSRF token and the session cookie is not SameSite - a cross-site request can set it to attacker@evil.com. The signature preview reads location.hash into innerHTML: prove execution via /settings#<img src=x onerror="fetch('/exam3/api/solve/dom')">. The "encrypted" backup key is just base64(XOR) with a key hiding in config.bak - reverse it.