8.8
CVSSv3

CVE-2025-24968

CVSSv4: NA | CVSSv3: 8.8 | CVSSv2: NA | VMScore: 980 | EPSS: 0.00043 | KEV: Not Included
Published: 04/02/2025 Updated: 04/02/2025

Vulnerability Summary

Unauthenticated Project Deletion Vulnerability in reNgine Reconnaissance Framework

reNgine, an automated reconnaissance framework for web applications, has a serious vulnerability in its project deletion mechanism. Users with roles like `penetration_tester` or `auditor` can delete all projects in the system, potentially leading to a complete system takeover. After deletion, attackers can be redirected to the onboarding page, where they can add or modify users, including Sys Admins, and configure critical settings such as API keys and user preferences. This security issue impacts all versions up to and including 2.20. The vulnerability currently has no known workarounds, and users are recommended to monitor the project for future releases that will address this problem.

Vulnerable Product Search on Vulmon Subscribe to Product

yogeshojha rengine