wger 是一款免费的、开源的运动和健身管理工具。在 wger 2.6 版本之前存在一个漏洞,涉及认证和会话生命周期的管理。具体而言,用户在注销或更改密码后,基于令牌(bearer-style)的 API 凭证仍然有效。如果攻击者窃取了受害者的 DRF 认证令牌(Authorization: Token ...)或 JWT 刷新令牌(JWT refresh token),他们可以在令牌被手动轮换/删除(DRF 令牌)或自然过期(JWT 刷新令牌)之前,继续访问受保护的 端点。wger 2.6 版本已包含对此漏洞的修
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| wger-project | wger | < 2.6 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-43976 | 7.1 HIGH | wger: cross-tenant admin notes/contracts leak via gym=None bypass (5 views) |
| CVE-2026-46434 | 7.1 HIGH | wger: Trainer Privilege Escalation - Improper Privilege Management |
| CVE-2026-46438 | 6.5 MEDIUM | wger: Cross-User Data Corruption via Missing Ownership Check on WorkoutLog.slot_entry |
| CVE-2026-45161 | 5.4 MEDIUM | wger: trainer_login accepts GET - CSRF bypass enables forced session rebinding |
No comments yet