ReNgine thru 2.2.0 is vulnerable to a Stored Cross-Site Scripting (XSS) vulnerability in the Vulnerabilities module. When scanning a target with an XSS payload, the unsanitized payload is rendered in the ReNgine web UI, resulting in arbitrary JavaScript execution in the victim's browser. This can be abused to steal session cookies, perform unauthorized actions, or compromise the ReNgine administrator's account.
Metrics
Affected Vendors & Products
References
History
Mon, 20 Oct 2025 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Yogeshojha
Yogeshojha rengine |
|
| Vendors & Products |
Yogeshojha
Yogeshojha rengine |
Fri, 10 Oct 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-79 | |
| Metrics |
cvssV3_1
|
Fri, 10 Oct 2025 14:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | ReNgine thru 2.2.0 is vulnerable to a Stored Cross-Site Scripting (XSS) vulnerability in the Vulnerabilities module. When scanning a target with an XSS payload, the unsanitized payload is rendered in the ReNgine web UI, resulting in arbitrary JavaScript execution in the victim's browser. This can be abused to steal session cookies, perform unauthorized actions, or compromise the ReNgine administrator's account. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published: 2025-10-10T00:00:00.000Z
Updated: 2025-10-10T14:23:44.425Z
Reserved: 2025-09-26T00:00:00.000Z
Link: CVE-2025-61319
Updated: 2025-10-10T14:23:39.112Z
Status : Awaiting Analysis
Published: 2025-10-10T14:15:43.500
Modified: 2025-10-14T19:36:59.730
Link: CVE-2025-61319
No data.
ReportizFlow