Stored XSS Vulnerability in reNgine Up to Version 2.1.2
reNgine is an automatic tool for web application checks. Versions 2.1.2 and below have a Stored Cross-Site Scripting (XSS) flaw. This flaw happens during domain scans. If the scanned domain's DNS record has an XSS payload, harmful scripts run in reNgine's dashboard when anyone views the scan results. The XSS payload comes straight from the DNS record of the scanned domain. Attackers can launch attacks without extra input from the target or reNgine user. A fix is available and should be in version 2.1.3.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
yogeshojha rengine |