Stored Cross-Site Scripting Vulnerability in reNgine by Yogesh Ojha
CVE-2025-24967

7.4HIGH

Key Information:

Vendor

Yogeshojha

Status
Vendor
CVE Published:
4 February 2025

What is CVE-2025-24967?

reNgine, an automated reconnaissance framework for web applications, is affected by a stored cross-site scripting vulnerability located in the user management functionality within its admin panel. Attackers can exploit this vulnerability to inject malicious scripts into the username field during user creation. If an administrator views or interacts with the entry, unauthorized scripts can execute, potentially compromising sensitive functionalities and data within the admin interface. All versions of reNgine up to and including 2.20 are vulnerable. No workarounds are available, and users are advised to monitor for updates addressing this security risk.

Affected Version(s)

rengine <= 2.2.0

References

CVSS V4

Score:
7.4
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.