VDB
EN
HIGH 8.8

PYSEC-2023-144

상세

Cross Site Request Forgery (CSRF) vulnerability in wger Project wger Workout Manager 2.2.0a3 allows a remote attacker to gain privileges via the user-management feature in the gym/views/gym.py, templates/gym/reset_user_password.html, templates/user/overview.html, core/views/user.py, and templates/user/preferences.html, core/forms.py components.

이 버전이 영향받나요?

사용 중인 패키지 버전을 입력하면 즉시 평가합니다.

영향 패키지

PyPI / wger
최초 영향 버전: 0

No fixed version published yet for wger (pip). Pin to a known-safe version or switch to an alternative.

참고