Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
wger: Privilege escalation via trainer-login session chaining allows gym trainers to impersonate gym managers
Vulnerability Description
wger is a free, open-source workout and fitness manager. In versions prior to 2.6, a gym trainer can escalate their session to any higher-privileged account (gym manager, general manager) by chaining two calls to the trainer-login endpoint. Once a trainer performs a legitimate switch into a low-privileged user, the session flag trainer.identity is set and this flag alone bypasses the permission check on all subsequent trainer-login calls. This grants full gym administration capabilities including viewing all member data, modifying contracts, managing gym configuration, and accessing other trainers' and managers' personal information. This issue has been fixed in version 2.6.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Vulnerability Type
特权管理不恰当
Vulnerability Title
wger 权限许可和访问控制问题漏洞
Vulnerability Description
wger是wger团队开源的一款自托管健身、营养和体重追踪器。 wger 2.6之前版本存在权限许可和访问控制问题漏洞,该漏洞源于权限许可和访问控制问题,可能导致健身教练通过两次调用trainer-login端点,将会话升级到任何高权限账户,从而获得完整的健身房管理能力,包括查看所有会员数据、修改合同、管理健身房配置以及访问其他教练和管理员的个人信息。
CVSS Information
N/A
Vulnerability Type
N/A