Количество 2
Количество 2
CVE-2023-38759
Cross Site Request Forgery (CSRF) vulnerability in wger Project wger Workout Manager 2.2.0a3 allows a remote attacker to gain privileges via the user-management feature in the gym/views/gym.py, templates/gym/reset_user_password.html, templates/user/overview.html, core/views/user.py, and templates/user/preferences.html, core/forms.py components.
GHSA-wrw3-qmqw-4x9w
wger Workout Manager Cross-Site Request Forgery vulnerability
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2023-38759 Cross Site Request Forgery (CSRF) vulnerability in wger Project wger Workout Manager 2.2.0a3 allows a remote attacker to gain privileges via the user-management feature in the gym/views/gym.py, templates/gym/reset_user_password.html, templates/user/overview.html, core/views/user.py, and templates/user/preferences.html, core/forms.py components. | CVSS3: 8.8 | 0% Низкий | больше 2 лет назад | |
GHSA-wrw3-qmqw-4x9w wger Workout Manager Cross-Site Request Forgery vulnerability | CVSS3: 8.8 | 0% Низкий | больше 2 лет назад |
Уязвимостей на страницу