Arunna Cross-Site Request Forgery Vulnerability

Vulnerability

A cross-site request forgery (CSRF) vulnerability has been identified in Arunna version 1.0.0. This vulnerability allows attackers to manipulate user profile settings without authentication. By crafting a malicious form, attackers can trick authenticated users into submitting it, thereby changing user details such as passwords, email addresses, and administrative privileges.

Impact

Exploitation of this vulnerability allows for unauthorized changes to user profile settings, including sensitive information such as passwords and email addresses, as well as administrative privileges.

Reproduction

To reproduce this vulnerability, an attacker must create a malicious form that includes the necessary fields to change user profile information. This form should be designed to be submitted by an authenticated user without their knowledge. Once the form is submitted, the user's profile settings will be altered according to the information provided in the form.

Added: Jan 15, 2026, 5:01 PM
Updated: Jan 15, 2026, 7:52 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
5.6
exploitability
7.7
remediation
0.0
relevance
2.1
threat
6.4
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.