This tester issues the exact request shape a real cross-site attacker page would produce - each carrying no valid CSRF token - against your own live session, so you can watch the state change and confirm the finding on Progress. Detection is server-side: a state change that succeeds under these shapes is the bug.
A real CSRF PoC is served from the attacker origin. Paste the HTML you would host - a self-submitting form or an <img> - to review its shape. (It is shown, not executed; the buttons above fire the live requests.)
(nothing fired yet)
More hands-on practice → labs.hackxpert.com