There's means of CSRF whenever malicious HTML or JavaScript which is targeted on your website is been embedded in another HTML page (or an email message) which is been successfully executed.
An example is the following which is been placed in another webpage which innocently asks for your name and age before proceeding: