Unrestricted Project Deletion Vulnerability in reNgine by Yogesh Ojha
CVE-2025-24968

8.8HIGH

Key Information:

Vendor

Yogeshojha

Status
Vendor
CVE Published:
4 February 2025

What is CVE-2025-24968?

The reNgine framework for automated web application reconnaissance contains a vulnerability that allows users with limited roles, such as 'penetration_tester' or 'auditor', to delete all projects within the system. This severe flaw can facilitate a complete takeover of the system as it exposes users to unauthorized access, potentially redirecting attackers to the onboarding interface. In this compromised state, attackers may add or alter user roles, including that of System Administrators, and manipulate crucial configurations like API keys and user preferences. This vulnerability affects all versions of reNgine up to and including 2.20, and users are strongly recommended to stay vigilant for updates that will address this security issue. Currently, there are no workarounds available.

Affected Version(s)

rengine <= 2.2.0

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-24968 : Unrestricted Project Deletion Vulnerability in reNgine by Yogesh Ojha