QID 994908

Date Published: 2023-08-21

QID 994908: Python (Pip) Security Update for wger (GHSA-wrw3-qmqw-4x9w)

Cross Site Request Forgery (CSRF) vulnerability in wger Project wger Workout Manager 2.2.0a3 allows a remote attacker to gain privileges via the user-management feature in the gym/views/gym.py, templates/gym/reset_user_password.html, templates/user/overview.html, core/views/user.py, and templates/user/preferences.html, core/forms.py components.

Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.

  • CVSS V3 rated as Critical - 8.8 severity.
  • CVSS V2 rated as Medium - 5.4 severity.
  • Solution
    Refer to Github security advisory GHSA-wrw3-qmqw-4x9w for updates and patch information.
    Vendor References

    CVEs related to QID 994908

    Software Advisories
    Advisory ID Software Component Link