Medium severity5.4GHSA Advisory· Published Oct 7, 2026· Updated Oct 7, 2026
CVE-2026-45161
CVE-2026-45161
Description
wger is a free, open-source workout and fitness manager. Prior to version 2.6, the trainer_login view in wger accepts GET requests and executes django_login() without any CSRF protection, because Django's CsrfViewMiddleware only enforces tokens on unsafe methods (POST/PUT/PATCH/DELETE). An attacker can embed a single `` tag on a malicious page; when an authenticated trainer loads that page, their browser auto-issues the GET with the session cookie, forcibly rebinding the trainer's session to an arbitrary user account. Version 2.6 fixes the issue.
Affected products
2<= 2.1+ 1 more
- (no CPE)range: <= 2.1
- (no CPE)
Patches
Vulnerability mechanics
References
3News mentions
0No linked articles in our index yet.