enA state change that succeeds while carrying your session cookie on a cross-site request is the SameSite finding - a SameSite=Strict cookie would have been withheld, and the server does no Origin/Referer check either. The PoC Tester issues the cross-site-shaped request for you.
More hands-on practice → labs.hackxpert.com