CVE-2023-38759: CSRF
Cross Site Request Forgery (CSRF) vulnerability in wger Project wger Workout Manager 2.2.0a3 allows a remote attacker to gain privileges via the user-management feature in the gym/views/gym.py, templates/gym/resetuserpassword.html, templates/user/overview.html, core/views/user.py, and templates/user/preferences.html, core/forms.py components.
Other sources
Cross Site Request Forgery (CSRF) vulnerability in wger Project wger Workout Manager 2.2.0a3 allows a remote attacker to gain privileges via the user-management feature in the gym/views/gym.py, templates/gym/resetuserpassword.html, templates/user/overview.html, core/views/user.py, and templates/user/preferences.html, core/forms.py components.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-38759?
CVE-2023-38759 is categorized as a high severity Cross Site Request Forgery (CSRF) vulnerability.
How do I fix CVE-2023-38759?
To fix CVE-2023-38759, update to the latest secure version of Wger Workout Manager that addresses this CSRF vulnerability.
Can CVE-2023-38759 be exploited remotely?
Yes, CVE-2023-38759 can be exploited by remote attackers via the user-management feature.
What software versions are affected by CVE-2023-38759?
CVE-2023-38759 affects Wger Workout Manager version 2.2.0a3 and earlier.
What components of the Wger Workout Manager are involved in CVE-2023-38759?
CVE-2023-38759 involves components such as `gym/views/gym.py`, `core/views/user.py`, and related templates.