Medium severity5.4NVD Advisory· Published Aug 8, 2023· Updated Jun 17, 2026
CVE-2023-38758
CVE-2023-38758
Description
Cross Site Scripting vulnerability in wger Project wger Workout Manager v.2.2.0a3 allows a remote attacker to gain privileges via the license_author field in the add-ingredient function in the templates/ingredients/view.html, models/ingredients.py, and views/ingredients.py components.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
wgerPyPI | <= 2.2.0a3 | — |
Affected products
3cpe:2.3:a:wger:workout_manager:2.2.0:a3:*:*:*:android:*:*+ 1 more
- cpe:2.3:a:wger:workout_manager:2.2.0:a3:*:*:*:android:*:*
- (no CPE)
Patches
Vulnerability mechanics
References
4- github.com/advisories/GHSA-8m9p-3926-gffrghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2023-38758ghsaADVISORY
- github.com/pypa/advisory-database/tree/main/vulns/wger/PYSEC-2023-143.yamlghsaWEB
- wger.denvdProductWEB
News mentions
0No linked articles in our index yet.