Executive brief
wger is a web-based fitness and gym management application used by trainers to manage client workouts and impersonation sessions. The trainer_login view fails to validate the redirect destination after a trainer enables impersonation mode, allowing an attacker to redirect the trainer to a malicious website. This can enable phishing attacks and leak sensitive information such as the impersonated user's ID through the browser's referrer header.
Technical details
The vulnerability is an open redirect (CWE-601) in the trainer_login view (wger/core/views/user.py, line 203) that fails to validate the 'next' GET parameter before redirecting via HttpResponseRedirect(). The vulnerable code performs no call to Django's url_has_allowed_host_and_scheme() function to ensure the redirect target is on the same host. An authenticated trainer with gym trainer permissions can be exploited by clicking a crafted link (e.g., /en/user/2/trainer-login?next=https://evil.example/steal). When the trainer enters impersonation mode, the view redirects to the attacker-controlled URL, leaking the impersonated user's user_pk via the Referer header. The fix involves adding host and scheme validation before the redirect. Patched in wger 2.6 and later.
Affected products
- wger wger <= 2.5.0
Timeline
- 2026-04-28: disclosed: GitHub Security Advisory published
- 2026-09-06: advisory: NVD and public advisory published
- 2026: patched: Fixed in wger 2.6 and later