Cross Site Request Forgery (CSRF) vulnerability in wger Project wger Workout Manager 2.2.0a3 allows a remote attacker to gain privileges via the user-management feature in the gym/views/gym.py, templates/gym/reset_user_password.html, templates/user/overview.html, core/views/user.py, and templates/user/preferences.html, core/forms.py components.
Cite this page
CVE-2023-38759. CVEDatabase.com. Retrieved 1 May 2026. https://cvedatabase.com/cve/CVE-2023-38759
Use CWE-352, Wger vendor hub and Workout Manager product page to widen CVE-2023-38759 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2023-38758 for nearby disclosures in the same product family.