Impact
The flaw resides in the trainer_login view of the wger application, where a GET request triggers a login without a CSRF check. By sending an forged GET request that the client’s browser automatically executes, an attacker can force the target trainer’s session to be rebound to an arbitrary user account. This results in the attacker assuming the identity of that account, enabling full access to its data and functions.
Affected Systems
wger, a free and open-source fitness manager provided by wger‑project, is affected in all releases prior to 2.6. Users running any version before the 2.6 release are vulnerable to this CSRF‑based session rebinding.
Risk and Exploitability
The vulnerability has a CVSS score of 5.4, indicating moderate severity. EPSS data is not available, and the issue is not listed in CISA's KEV catalog, suggesting that widespread exploitation has not yet been observed. In practice, exploitation requires the trainer to visit a malicious page that contains a simple image tag pointing to the vulnerable endpoint, and the trainer must already have an authenticated session. Once satisfied, the attacker can rebind that session to any account, effectively hijacking the trainer’s identity. The attack vector is client‑side, relying on a CSRF bypass of GET requests.
OpenCVE Enrichment
Github GHSA