| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-xf64-4pmc-h8qf | wger: trainer_login accepts GET - CSRF bypass enables forced session rebinding |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Wed, 07 Oct 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 07 Oct 2026 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Wger-project
Wger-project wger |
|
| Vendors & Products |
Wger-project
Wger-project wger |
Wed, 07 Oct 2026 14:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | wger is a free, open-source workout and fitness manager. Prior to version 2.6, the `trainer_login` view in wger accepts GET requests and executes `django_login()` without any CSRF protection, because Django's `CsrfViewMiddleware` only enforces tokens on unsafe methods (POST/PUT/PATCH/DELETE). An attacker can embed a single `<img>` tag on a malicious page; when an authenticated trainer loads that page, their browser auto-issues the GET with the session cookie, forcibly rebinding the trainer's session to an arbitrary user account. Version 2.6 fixes the issue. | |
| Title | wger: trainer_login accepts GET - CSRF bypass enables forced session rebinding | |
| Weaknesses | CWE-352 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-10-07T17:04:45.845Z
Reserved: 2026-05-08T20:44:38.965Z
Link: CVE-2026-45161
Updated: 2026-10-07T15:27:06.390Z
Status : Deferred
Published: 2026-10-07T14:17:10.087
Modified: 2026-10-07T17:16:55.703
Link: CVE-2026-45161
No data.
OpenCVE Enrichment
Updated: 2026-10-07T15:45:06Z
Github GHSA