ReNgine Stored Cross-Site Scripting Vulnerability

Vulnerability

A stored cross-site scripting vulnerability has been identified in ReNgine versions through 2.2.0, specifically within the Vulnerabilities module. This issue allows for the injection of unsanitized XSS payloads during target scans, which are then executed as arbitrary JavaScript in the context of the victim's browser. This vulnerability could be exploited to hijack session cookies, perform unauthorized actions, or compromise the ReNgine administrator's account.

Impact

Exploitation of this vulnerability allows for session hijacking, unauthorized actions on behalf of the administrator, and a general compromise of the admin's account.

Reproduction

To reproduce this vulnerability, scan a target with a URL parameter containing an XSS payload, such as a SVG image with an 'onload' event. After the scan, the injected payload will execute in the administrator's browser when the results are viewed in the Vulnerabilities tab.

Remediation

Users are advised to sanitize and escape user-supplied input before displaying scan results. Proper HTML encoding should be implemented for any user-controlled output in the Vulnerabilities tab.

Added: Oct 10, 2025, 2:18 PM
Updated: Oct 10, 2025, 3:19 PM

Vulnerability Rating

Custom Algorithm
spread
0.3
impact
5.4
exploitability
7.4
remediation
0.0
relevance
0.7
threat
6.4
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.