wger 是一款免费且开源的健身训练与健康管理软件。在 2.6 版本之前,wger 中有五个健身房管理视图存在缺陷:它们使用了不正确的健身房范围检查机制( ),当两个操作数均为 时,该检查会静默通过。拥有 和 权限但未关联任何健身房(即 )的训练师,可以读取实例中任何其他未关联用户的私人管理员备注、上传的文档、健身房合同、用户配置以及用户权限数据。后续的查询集仅根据攻击者提供的 进行过滤,缺乏额外的健身房范围验证,从而导致所有相关记录被泄露。该问题已在版本 2.6 中修复。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| wger-project | wger | < 2.6 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-46434 | 7.1 HIGH | wger: Trainer Privilege Escalation - Improper Privilege Management |
| CVE-2026-46438 | 6.5 MEDIUM | wger: Cross-User Data Corruption via Missing Ownership Check on WorkoutLog.slot_entry |
| CVE-2026-45161 | 5.4 MEDIUM | wger: trainer_login accepts GET - CSRF bypass enables forced session rebinding |
| CVE-2026-46437 | 4.8 MEDIUM | wger: API credentials remain valid after logout/password change |
No comments yet