Cross-Site Request Forgery Vulnerability in wger-project's Password Reset Function
CVE-2026-82544
5.3MEDIUM
What is CVE-2026-82544?
A vulnerability has been identified in the wger Workout Manager that affects the password reset functionality located in the gym.py file. This flaw enables an attacker to manipulate requests leading to unauthorized actions, potentially compromising user accounts through cross-site request forgery (CSRF). This type of attack can be executed remotely, emphasizing the need for implementing the provided patch to safeguard against exploitation.
Affected Version(s)
wger 2.6.0-alpha2
