Instead of hijacking the victim, plant them inside an account you control. Forge the sign-in.
Sign in
The victim is browsing while logged in. This login form has no CSRF protection.
Force the victim's browser to log in as your account, so their activity lands in it.
Victim is currently signed in as
victim
Your attacker account credentials (yours to give away):