Open redirect in wger - #VU128289

 

Open redirect in wger - #VU128289

Published: April 28, 2026


Vulnerability identifier: #VU128289
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-601
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to redirect a victim's browser to an attacker-controlled site and disclose sensitive information.

The vulnerability exists due to url redirection to an untrusted site in the trainer_login view when handling a crafted ?next= parameter. A remote user can send a crafted link to redirect a victim's browser to an attacker-controlled site and disclose sensitive information.

User interaction is required, and exploitation occurs after the trainer successfully enters impersonation mode.


Affected software

wger

Remediation

Install security update from vendor's website.

wger - update to 2.6

External References

Related Security Bulletins