Impact
A flaw in the wger password reset endpoint, reset_user_password, allows cross‑site request forgery. The CVE states that an attacker can trigger this flaw remotely. The effect of the vendor’s description is that an attacker could reset a victim’s password, which would enable the attacker to authenticate as that victim. Because the CVE does not explicitly state that the attacker would gain full control, this outcome is inferred from the described ability to change the password.
Affected Systems
The vulnerability affects all installations of wger up to version 2.6.0‑alpha2. Any deployment using those releases and the exposed password reset endpoint could be exploited.
Risk and Exploitability
The CVSS score of 5.3 suggests a moderate impact. The EPSS score is unavailable and the flaw is not listed in the CISA KEV catalog, so the current exploitation likelihood is uncertain. The description indicates that an attack is possible remotely, but the CVE does not specify whether the endpoint requires authentication or includes CSRF protection; thus, the exact ease of exploitation is unclear. Based on typical CSRF scenarios, an attacker with a crafted request could potentially reset a password, but the definitive risk depends on the actual deployment configuration.
OpenCVE Enrichment