Unrated severityNVD Advisory· Published Jan 15, 2026· Updated Apr 7, 2026
Arunna 1.0.0 - 'Multiple' Cross-Site Request Forgery (CSRF)
CVE-2021-47754
Description
Arunna 1.0.0 contains a cross-site request forgery vulnerability that allows attackers to manipulate user profile settings without authentication. Attackers can craft a malicious form to change user details, including passwords, email, and administrative privileges by tricking authenticated users into submitting the form.
Affected products
2- Arunna/Arunnav5Range: 1.0.0
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- web.archive.org/web/20211216074128/https://lyhinslab.org/index.php/2021/11/29/how-white-box-hacking-works-xss-csrf-in-arunna/mitreexploittechnical-description
- www.exploit-db.com/exploits/50608mitreexploit
News mentions
0No linked articles in our index yet.