PortSwigger's "CSRF vulnerability with no defenses" Walkthrough
This post covers the “no defenses” CSRF lab from PortSwigger. This lab is the only Apprentice-level lab within the OS command injection category. Before we get started, you’ll need a Portswigger