HTML Injection Vulnerability in reNgine Web Application Framework
CVE-2025-24966

5.3MEDIUM

Key Information:

Vendor

Yogeshojha

Status
Vendor
CVE Published:
4 February 2025

What is CVE-2025-24966?

The reNgine framework for automated reconnaissance has a critical vulnerability in its 'Add Target' feature. This vulnerability arises from inadequate validation of user inputs in the 'Target Organization' and 'Target Description' fields, enabling attackers to inject malicious HTML code. When executed, this code can lead to unauthorized actions or the theft of sensitive information. As a result, user trust and the integrity of the framework may be severely compromised. All versions of reNgine up to 2.2.0 are affected, and users should stay vigilant for updates aimed at resolving this issue, as there are currently no known workarounds.

Affected Version(s)

rengine <= 2.2.0

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.