Of course!
I am very interested in this topic, but I think that OxWall if you do not disable the csrf functions is very safe.
It may be enough to disable them except for the administrator and moderators.
Certainly your test code works if I run it with the same browser.