PT-2025-41564 · Rengine · Rengine

Amaljafarzade

·

Published

2025-10-10

·

Updated

2025-10-10

·

CVE-2025-61319

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions ReNgine versions through 2.2.0
Description ReNgine through version 2.2.0 contains a Stored Cross-Site Scripting (XSS) issue within the Vulnerabilities module. When a target is scanned using an XSS payload, the payload is rendered without proper sanitization in the ReNgine web user interface. This allows for the execution of arbitrary JavaScript code in the browser of a victim. This could potentially lead to the theft of session cookies, unauthorized actions, or compromise of administrator accounts. The vulnerable component renders unsanitized payloads from scans.
Recommendations Update ReNgine to a version later than 2.2.0.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2025-61319

Affected Products

Rengine