NA
CVSSv3

CVE-2025-24967

CVSSv4: 7.4 | CVSSv3: NA | CVSSv2: NA | VMScore: 840 | EPSS: 0.00093 | KEV: Not Included
Published: 04/02/2025 Updated: 04/02/2025

Vulnerability Summary

Stored XSS Vulnerability in reNgine Admin Panel User Management

reNgine, an automated reconnaissance framework for web applications, has a stored Cross Site Scripting (XSS) vulnerability in its admin panel's user management feature. An attacker can inject harmful scripts into the username field when creating a user. This vulnerability enables unauthorized script execution whenever an admin views or interacts with the affected user entry. The security issue threatens sensitive admin functionalities and impacts all versions up to and including 2.20. There are currently no known workarounds, and users are recommended to track the project for future releases that will address this vulnerability.

Vulnerable Product Search on Vulmon Subscribe to Product

yogeshojha rengine