Junglewise Threat Intelligence

CVE-2023-38758: PYSEC-2023-143 - Cross Site Scripting vulnerability in wger Project wger Workout Manager v.2.2.0a3 allows a remote attacker to gain privileges via the licens

CVE-2023-38758 · Severity: low · CVSS 3.1 · Published 2023-08-08

Technologies: wger (PyPI). Vendors: PyPI.

Executive brief

Cross Site Scripting vulnerability in wger Project wger Workout Manager v.2.2.0a3 allows a remote attacker to gain privileges via the license_author field in the add-ingredient function in the templates/ingredients/view.html, models/ingredients.py, and views/ingredients.py components.

Affected products

  • PyPI wger

Related threats