Lucene search

K
cvelistMitreCVELIST:CVE-2023-38759
HistoryAug 08, 2023 - 12:00 a.m.

CVE-2023-38759

2023-08-0800:00:00
mitre
www.cve.org
cross site request forgery
wger project
workout manager
remote attacker
user-management
gym
templates
core views
components

9.2 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

30.5%

Cross Site Request Forgery (CSRF) vulnerability in wger Project wger Workout Manager 2.2.0a3 allows a remote attacker to gain privileges via the user-management feature in the gym/views/gym.py, templates/gym/reset_user_password.html, templates/user/overview.html, core/views/user.py, and templates/user/preferences.html, core/forms.py components.

9.2 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

30.5%

Related for CVELIST:CVE-2023-38759