01-06-23, 03:29 PM (This post was last modified: 01-06-23, 03:32 PM by @zapedios.)
Info: The email change/SMS login... function on this page is vulnerable to CSRF. It tries to block CSRF attacks, but only applies defenses to certain types of requests. Example of CSRF in image: