PT-2026-83562 · Wger · Wger
CVSS v4.0
5.3
Medium
| Vector | AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X |
Name of the Vulnerable Software and Affected Versions
wger-project wger versions prior to 2.6.0-alpha2
Description
A flaw in the Password Reset component allows for remote cross-site request forgery (CSRF), a type of attack that forces an authenticated user to execute unwanted actions on a web application. The issue resides in the
reset user password() function within the wger/gym/views/gym.py file.Recommendations
Apply patch 3c6ce4b7f3eeafeb35318c6c4e82b1a3fd28b314 to versions prior to 2.6.0-alpha2.
As a temporary mitigation, restrict access to the
reset user password() function until the patch is applied.Exploit
Fix
CSRF
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Wger