Vulnerability Description
Cross Site Request Forgery (CSRF) vulnerability in wger Project wger Workout Manager 2.2.0a3 allows a remote attacker to gain privileges via the user-management feature in the gym/views/gym.py, templates/gym/reset_user_password.html, templates/user/overview.html, core/views/user.py, and templates/user/preferences.html, core/forms.py components.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Wger | Workout Manager | 2.2.0 |
Related Weaknesses (CWE)
References
- https://github.com/0x72303074/CVE-DisclosuresThird Party Advisory
- https://wger.deProduct
- https://github.com/0x72303074/CVE-DisclosuresThird Party Advisory
- https://wger.deProduct
FAQ
What is CVE-2023-38759?
CVE-2023-38759 is a vulnerability with a CVSS score of 8.8 (HIGH). Cross Site Request Forgery (CSRF) vulnerability in wger Project wger Workout Manager 2.2.0a3 allows a remote attacker to gain privileges via the user-management feature in the gym/views/gym.py, templa...
How severe is CVE-2023-38759?
CVE-2023-38759 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-38759?
Check the references section above for vendor advisories and patch information. Affected products include: Wger Workout Manager.