A Flask application with a login (admin/admin) and a form that stores the user's favourite colour in their profile. The state-changing POST has no anti-CSRF token.
Not startedDockercommit 9149439x86_64 · aarch64Secret
Build a page on another origin that silently changes the logged-in victim's favourite colour (cross-site request forgery).
The brief for this lab lives in its repository.