Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-24968

Опубликовано: 04 фев. 2025
Источник: nvd
CVSS3: 8.8
EPSS Низкий

Описание

reNgine is an automated reconnaissance framework for web applications. An unrestricted project deletion vulnerability allows attackers with specific roles, such as penetration_tester or auditor to delete all projects in the system. This can lead to a complete system takeover by redirecting the attacker to the onboarding page, where they can add or modify users, including Sys Admins, and configure critical settings like API keys and user preferences. This issue affects all versions up to and including 2.20. Users are advised to monitor the project for future releases which address this issue. There are no known workarounds.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:yogeshojha:rengine:*:*:*:*:*:*:*:*
Версия до 2.2.0 (включая)

EPSS

Процентиль: 44%
0.00216
Низкий

8.8 High

CVSS3

Дефекты

CWE-284
NVD-CWE-noinfo

EPSS

Процентиль: 44%
0.00216
Низкий

8.8 High

CVSS3

Дефекты

CWE-284
NVD-CWE-noinfo