reNgine HTML Injection Vulnerability in Target Organization and Description Fields

Vulnerability

A moderate HTML injection vulnerability has been identified in reNgine, an automated reconnaissance framework for web applications, affecting all versions up to and including 2.2.0. The issue arises in the 'Add Target' functionality, where the Target Organization and Target Description fields improperly validate user inputs, allowing the injection of arbitrary HTML. Exploitation of this vulnerability could lead to unauthorized actions, theft of sensitive information, and manipulation of user actions, potentially damaging the organization's reputation and customer trust.

Impact

Exploitation of this vulnerability can compromise the application's integrity and user trust, allowing attackers to execute unauthorized actions, steal sensitive information, or manipulate users into performing harmful actions. This could negatively affect the organization's reputation, customer trust, and regulatory compliance.

Reproduction

To reproduce this vulnerability, log into the application and navigate to the 'Target' section. Click on 'Add Target' and insert an HTML payload, such as a heading tag, into the Target Organization and Target Description fields. After submitting the form, the injected HTML will be executed in the target area, demonstrating the vulnerability.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.8
impact
5.0
exploitability
6.3
remediation
0.0
relevance
0.0
threat
6.4
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.