This page demonstrates that https://acumbamail.com returns Access-Control-Allow-Origin: *
Testing...
Simulated: document.cookie.match(/csrftoken=([^;]+)/)[1]
Testing...
1. Attacker hosts this page on evil.com
2. Victim visits while logged into acumbamail.com
3. CORS wildcard allows this page to read acumbamail responses
4. If any XSS exists, attacker steals csrftoken (no HttpOnly)
5. Attacker forges POST requests to change account settings
6. Account compromised