CVE-2026-45161: wger: trainer_login accepts GET - CSRF bypass enables forced session rebinding
### Summary The `trainer_login` view in wger accepts GET requests and executes `django_login()` without any CSRF protection, because Django's `CsrfViewMiddleware` only enforces tokens on unsafe methods...