在 wger-project 的 wger(版本至 2.6.0-alpha2)中发现了一个缺陷。该问题影响 wger/gym/views/gym.py 文件中密码重置组件的 reset_user_password 函数。执行特定操作可能导致跨站请求伪造(CSRF)漏洞。该攻击可远程发起。修复该问题的补丁编号为 3c6ce4b7f3eeafeb35318c6c4e82b1a3fd28b314。建议应用此补丁以修复该问题。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| wger-project | wger | 2.6.0-alpha2 |
cpe:2.3:a:wger-project:wger:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet