GHSA-wrw3-qmqw-4x9w
Dashboard / Vulnerabilities / GHSA-wrw3-qmqw-4x9w
GHSA-wrw3-qmqw-4x9w
Summary: wger Workout Manager Cross-Site Request Forgery vulnerability
Details: Cross Site Request Forgery (CSRF) vulnerability in wger Project wger Workout Manager 2.2.0a3 allows a remote attacker to gain privileges via the `user-management` feature in the `gym/views/gym.py`, `templates/gym/reset_user_password.html`, `templates/user/overview.html`, `core/views/user.py`, and `templates/user/preferences.html`, `core/forms.py` components.
References: https://nvd.nist.gov/vuln/detail/CVE-2023-38759, https://github.com/0x72303074/CVE-Disclosures, https://github.com/pypa/advisory-database/tree/main/vulns/wger/PYSEC-2023-144.yaml, https://github.com/wger-project/wger, https://wger.de
Affected packages
Package
Name: wger
Purl: pkg:pypi/wger
Affected ranges
Type: ECOSYSTEM
Events:
