This page demonstrates the CSRF vulnerability in BDServer.
If you are logged into BDServer at localhost:8080, your profile has been modified.
BDServer uses GET requests for state-changing operations and has no CSRF protection. When your browser loads this page, it fetches the image URLs above. Since you're logged in, your session cookie is sent with each request, authenticating the malicious actions as if you performed them yourself.