Description
Arunna 1.0.0 contains a cross-site request forgery vulnerability that allows attackers to manipulate user profile settings without authentication. Attackers can craft a malicious form to change user details, including passwords, email, and administrative privileges by tricking authenticated users into submitting the form.
Problem types
Cross-Site Request Forgery (CSRF)
Product status
Credits
=(L_L)=
References
www.exploit-db.com/exploits/50608
web.archive.org/...ite-box-hacking-works-xss-csrf-in-arunna/
www.exploit-db.com/exploits/50608 (ExploitDB-50608)
web.archive.org/...ite-box-hacking-works-xss-csrf-in-arunna/ (Archived Researcher Blog)
github.com/arunna/arunna (Arunna GitHub Repository)