Google Security Issue #3: Light CSRF on Google Analytics
July 14, 2011Light meaning the damage is minor, but still a CSRF. You could delete all scheduled e-mails, this is how it used to work:
If you go to Google Analytics->My Customization->Email.
The following call is not protected: