In fact, every time somebody choose flask over Django, I ask what they are going to do about CSRF, only to get a blank stare. Same with manual PHP or using most nodejs web libs.
There are so many websites that are vulnerable to this, and it's something we know well, and have solutions for. Imagine what we don't know about. The internet is really made of swiss cheese.