Identifying email change functionality is vulnerable to CSRF.
Identify that the applications correctly validate the token when it is present but skip the validation if the token is omitted.
Using exploit server to host an HTML page that uses a CSRF attack to change the viewer's email address.