> to make ‘GET’ requests, meaning they could <not> send data to them.
no way, I refuse to believe this is quote from that report. Can someone please point out what I'm missing here?
You're not missing anything. TFA really state this wrong assumption in their own voice.
I think it’s just to distinguish two stages of the attack. They figured out how to make get requests, then how to use that to make others which was required for accessing the sandbox on modal iiuc.