WEB 001 - CSRF

Captured: flag{cwap_csrf_no_token_state_change}
Your account email: attacker@evil.com

The change-email endpoint takes a plain POST with no CSRF token and the session cookie is not SameSite. Host a cross-site auto-submitting form that sets the email to attacker@evil.com (simulate it here):


CWAP Prep Labs · HackXpert Coaching · The XSS Rat · authorized lab use only