Finding Your First Bug: Cross-Site Request Forgery (CSRF)