wger 2.6 之前的版本(受影响的版本 ≤ 2.5.0)在 视图( )中存在一个开放重定向漏洞。当训练员进入“模拟登录”(impersonation)模式后,该视图会直接通过 将请求重定向到用户通过 GET 参数 提供的值,而在使用 进行校验之前就直接执行了跳转。攻击者可以向已认证的训练员发送一个精心构造的链接,使其浏览器被重定向到攻击者控制的域名,从而实施钓鱼攻击,并可能通过 Referer 请求头泄露 wger 的 URL 结构(包括被模拟用户的 )。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| wger-project | wger | < 2.6 |
affected |
2.6 |
unaffected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| wger-project | wger | 0 ~ 2.6 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-86254 | 6.8 MEDIUM | wger Incomplete Authorization Fix Cross-Tenant Account Deletion |
| CVE-2026-86255 | 6.5 MEDIUM | wger before 2.5 Uncontrolled Resource Consumption via date_sequence |
| CVE-2026-86257 | 5.4 MEDIUM | wger before 2.6 CSV Formula Injection via member export |
No comments yet