PT-2024-30543 · Rengine · Rengine

Touhidshaikh

·

Published

2024-08-16

·

Updated

2024-09-11

·

CVE-2024-43381

CVSS v3.1

5.0

Medium

VectorAV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions reNgine versions 2.1.2 and prior
Description The issue occurs when scanning a domain, and if the target domain's DNS record contains an XSS payload, it leads to the execution of malicious scripts in the reNgine's dashboard view when any user views the scan results. The XSS payload is directly fetched from the DNS record of the remote target domain. Consequently, an attacker can execute the attack without requiring any additional input from the target or the reNgine user.
Recommendations For versions 2.1.2 and prior, update to version 2.1.3 or later, which is expected to include a patch for this issue. As a temporary workaround, consider restricting access to the dashboard view or disabling the scanning feature for domains with potentially malicious DNS records until the patch is applied.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-43381
GHSA-96Q4-FJ2M-JQF7

Affected Products

Rengine