After the CSRF attack succeeds, the flag is displayed on the confirmation page inside the attacker frame.
Output
HackrGG{csrf_f0rc3d_4cc0unt_upd4t3}
⚑ A real CSRF attack could change passwords, transfer funds, or modify any state-changing endpoint that lacks token validation.