HTML Injection Vulnerability in reNgine Web Application Framework
CVE-2025-24966
5.3MEDIUM
What is CVE-2025-24966?
The reNgine framework for automated reconnaissance has a critical vulnerability in its 'Add Target' feature. This vulnerability arises from inadequate validation of user inputs in the 'Target Organization' and 'Target Description' fields, enabling attackers to inject malicious HTML code. When executed, this code can lead to unauthorized actions or the theft of sensitive information. As a result, user trust and the integrity of the framework may be severely compromised. All versions of reNgine up to 2.2.0 are affected, and users should stay vigilant for updates aimed at resolving this issue, as there are currently no known workarounds.
Affected Version(s)
rengine <= 2.2.0