Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Sun, 30 Aug 2026 14:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw has been found in wger-project wger up to 2.6.0-alpha2. This issue affects the function reset_user_password of the file wger/gym/views/gym.py of the component Password Reset. Executing a manipulation can lead to cross-site request forgery. It is possible to launch the attack remotely. This patch is called 3c6ce4b7f3eeafeb35318c6c4e82b1a3fd28b314. It is advisable to implement a patch to correct this issue. | |
| Title | wger-project wger Password Reset gym.py reset_user_password cross-site request forgery | |
| First Time appeared |
Wger-project
Wger-project wger |
|
| Weaknesses | CWE-352 CWE-862 |
|
| CPEs | cpe:2.3:a:wger-project:wger:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Wger-project
Wger-project wger |
|
| References |
|
|
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-08-30T13:45:09.773Z
Reserved: 2026-08-29T17:50:40.329Z
Link: CVE-2026-82544
No data.
Status : Received
Published: 2026-08-30T14:17:02.627
Modified: 2026-08-30T14:17:02.627
Link: CVE-2026-82544
No data.
OpenCVE Enrichment
Updated: 2026-08-30T17:15:04Z