Goal: Make your profile become admin even though the UI only looks like a username update form.
Mass assignment happens when the server blindly maps client-supplied fields onto an internal object. Hidden inputs are still attacker-controlled.
Username: User
Account Type: user
Bio: I love cheese labs.