5.4
CVSSv3

CVE-2024-43381

CVSSv4: NA | CVSSv3: 5.4 | CVSSv2: NA | VMScore: 640 | EPSS: 0.00183 | KEV: Not Included
Published: 16/08/2024 Updated: 11/09/2024

Vulnerability Summary

Stored XSS Vulnerability in reNgine Up to Version 2.1.2

reNgine is an automatic tool for web application checks. Versions 2.1.2 and below have a Stored Cross-Site Scripting (XSS) flaw. This flaw happens during domain scans. If the scanned domain's DNS record has an XSS payload, harmful scripts run in reNgine's dashboard when anyone views the scan results. The XSS payload comes straight from the DNS record of the scanned domain. Attackers can launch attacks without extra input from the target or reNgine user. A fix is available and should be in version 2.1.3.

Vulnerable Product Search on Vulmon Subscribe to Product

yogeshojha rengine