Impact
In versions prior to 2.6, a gym trainer can chain two calls to the trainer‑login endpoint to elevate their privileges to any higher‑level account, such as gym manager or general manager. After a legitimate switch into a low‑privileged user, the session flag trainer.identity is set, and this flag alone bypasses permission checks on all subsequent trainer‑login calls. This flaw grants full gym administrative rights, allowing the trainer to view all member data, modify contracts, manage gym configuration, and access personal information of other trainers and managers. The vulnerability stems from improper privilege validation, identified as CWE‑269.
Affected Systems
wger, the open‑source workout and fitness manager, before version 2.6 is affected. Users running any release prior to 2.6 may be vulnerable to this privilege escalation.
Risk and Exploitability
The CVSS score of 8.1 indicates a high severity, while the EPSS score of less than 1 % shows that exploitation is unlikely at present. The flaw is not listed in the CISA KEV catalog, and no public exploits have been to hit the the flag is set, all further permission checks are ignored, providing complete administrative control over the gym’s data and configuration.
OpenCVE Enrichment
Github GHSA