GHSA-8m9p-3926-gffr
GitHub Security Advisory
wger Workout Manager Cross-site Scripting vulnerability
✓ GitHub Reviewed
MODERATE
Has CVE
Advisory Details
Cross Site Scripting vulnerability in wger Project wger Workout Manager v.2.2.0a3 allows a remote attacker to gain privileges via the `license_author `field in the add-ingredient function in the `templates/ingredients/view.html`, `models/ingredients.py`, and `views/ingredients.py` components.
Affected Packages
PyPI
wger
Affected versions:
0
(last affected: 2.2.0a3)
Related CVEs
Key Information
5.0
/10
Dataset
Last updated: July 30, 2025 6:36 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.