In 2007, Gmail had a XSRF vulnerability for setting up filters. It was exploited by attackers that would create a filter
'Contains "password"', 'Forward to: evil@example.com', 'Run on all messages'.
Basically you could visit a malicious webpage, and all emails containing the word "password", would be sent to the attacker.
Basically you could visit a malicious webpage, and all emails containing the word "password", would be sent to the attacker.