There is no CSRF token implemented in business-central so the CSRF attack is possible. Attackers are able to cause unwanted modificiation of the target's instance by leading the users who are trusted to a specially-crafted web page.
Acknowledgments: Name: Jeremy Choi (Red Hat Product Security Team)