This is the CWAP Module 05 practice pack for Cross-Site Request Forgery. Each mini-lab is isolated. The demo session cookie is deliberately not SameSite=Strict, so cross-site requests carry it. Prove each finding by firing the malicious request shape - the PoC Tester does it for you - then check Progress.
Each is a minimal app with exactly ONE exploitable finding. No hunting required.
Realistic apps. You must search, map every state change, and develop a method.
More hands-on practice → labs.hackxpert.com