Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-45161— wger: trainer_login accepts GET - CSRF bypass enables forced session rebinding

Quick assessment

Affected
wger-project wger
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

wger 是一款免费且开源的健身与训练管理软件。在 2.6 版本之前,wger 的 视图会接受 GET 请求,并在未进行任何 CSRF(跨站请求伪造)保护的情况下执行 。由于 Django 的 仅对非安全方法(如 POST、PUT、PATCH、DELETE)强制校验 CSRF 令牌,因此对 GET 请求不作保护。 攻击者可以在恶意页面中嵌入一个单行的 标签。当已认证的教练用户访问该页面时,其浏览器会自动携带会话 Cookie 发起 GET 请求,从而导致教练的会话被强制绑定到一个任意用户账户。此问题已在 wger

CVSS 5.4 · Medium

Possible ATT&CK Techniques 1 AI

T1110 · Brute Force
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-45161

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
wger: trainer_login accepts GET - CSRF bypass enables forced session rebinding
Source: CVE Program / CVE List V5
Vulnerability Description
wger is a free, open-source workout and fitness manager. Prior to version 2.6, the `trainer_login` view in wger accepts GET requests and executes `django_login()` without any CSRF protection, because Django's `CsrfViewMiddleware` only enforces tokens on unsafe methods (POST/PUT/PATCH/DELETE). An attacker can embed a single `<img>` tag on a malicious page; when an authenticated trainer loads that page, their browser auto-issues the GET with the session cookie, forcibly rebinding the trainer's session to an arbitrary user account. Version 2.6 fixes the issue.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
跨站请求伪造(CSRF)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
wger-project wger < 2.6 -

II. Public POCs for CVE-2026-45161

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-45161

请登录查看更多情报信息。

Other References for CVE-2026-45161 (2)

Same Patch Batch · wger-project · 2026-10-07 · 5 CVEs total

CVE-2026-43976 7.1 HIGH wger: cross-tenant admin notes/contracts leak via gym=None bypass (5 views)
CVE-2026-46434 7.1 HIGH wger: Trainer Privilege Escalation - Improper Privilege Management
CVE-2026-46438 6.5 MEDIUM wger: Cross-User Data Corruption via Missing Ownership Check on WorkoutLog.slot_entry
CVE-2026-46437 4.8 MEDIUM wger: API credentials remain valid after logout/password change

IV. Related Vulnerabilities

V. Comments for CVE-2026-45161

No comments yet


Leave a comment