PT-2026-86526 · Wger · Wger
CVSS v3.1
7.4
High
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
wger versions prior to 2.6
Description
The application fails to sanitize the
first name and last name fields within the gym member TSV export endpoint. This allows a gym member to perform CSV Injection by inserting spreadsheet formulas, such as =HYPERLINK, into these fields. When an administrator opens the exported file using software like Excel or LibreOffice Calc, these formulas can be executed to exfiltrate administrative data or run arbitrary code.Recommendations
Update wger to version 2.6 or later.
As a temporary mitigation, restrict the use of the gym member TSV export endpoint until the update is applied.
Exploit
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Wger