In JetBrains YouTrack prior to 2020.4.4701, CSRF via attachment upload was possible.
jetbrains youtrack