Naked - token never validated

password changed = False

Change password

This form does carry a csrf_token field (your token is csrf-demo-8f14e45fceea), but the server never validates it. Send it blank, send junk, or drop it - the change still applies. Any request whose token is not the real one proves the field is decorative. The PoC Tester fires a blank-token request.

More hands-on practice → labs.hackxpert.com