A $3,500-Worth HTML Injection by Abusing CSRF-like

Chaining a Low-Severity HTML Injection with Same-Site Request Forgery to Escalate Impact.