Hacktivity from 7seciq
https://hackerone.com/reports/99857
Request Accepts without X-CSRFToken [ Header - Cookie ]
https://hackerone.com/reports/99857