Sensitive Information Exposure in reNgine Automated Reconnaissance Framework
CVE-2025-24899
7.1HIGH
What is CVE-2025-24899?
A significant vulnerability exists in the reNgine automated reconnaissance framework, allowing an insider attacker to exploit the system and extract sensitive user information from other users. Roles such as Auditor, Penetration Tester, or Systems Administrator can be exploited to issue a GET request to retrieve critical details, including usernames, passwords, emails, roles, and personal activity logs. This vulnerability emphasizes the importance of restricting access based on user roles and necessitates an immediate upgrade to version 2.2.0 to mitigate risks effectively. There are currently no workarounds available.
Affected Version(s)
rengine < 2.2.0