The change-email endpoint takes a plain POST with no CSRF token and the session cookie is not SameSite. Host a cross-site auto-submitting form that sets the email to attacker@evil.com (simulate it here):
CWAP Prep Labs · HackXpert Coaching · The XSS Rat · authorized lab use only