# Exploit Title: Arunna 1.0.0 - 'Multiple' Cross-Site Request Forgery (CSRF) # Date: November 29, 2021 # Exploit Author: =(L_L)= # Detailed Bug Description: https://lyhinslab.org/index.php/2021/11/29/how-white-box-hacking-works-xss-csrf-in-arunna/ # Vendor Homepage: https://github.com/arunna # Software Link: https://github.com/arunna/arunna # Version: 1.0.0 # Tested on: Ubuntu 20.04.2 LTS
username[0]
select[0]
first_name[0]
last_name[0]
display_name[0]
one_liner[0]
location[0]
sex[0]
birthday[0]
birthmonth[0]
birthyear[0]
bio[0]
expertise[0][]
tags[0]
skills[0]
email[0]
website[0]
password[0]
re_password[0]
user_type[0]
status[0]
save_changes