CVEs affecting projects tracked on Release Alert, from NVD & OSV.
CVE-2023-50094 — HIGH severity vulnerability | Release Alert
CVE-2023-50094
8.8
HIGHCVSS v3
Published
January 1, 2024
Affected
1 project
Assigned by
MITRE
Severity scale
010
Description
reNgine before 2.1.2 allows OS Command Injection if an adversary has a valid session ID. The attack places shell metacharacters in an api/tools/waf_detector/?url= string. The commands are executed as root via subprocess.check_output.
GitHubreNgine is an automated reconnaissance framework for web applications with a focus on highly configurable streamlined recon process via Engines, recon data correlation and organization, continuous monitoring, backed by a database, and simple yet intuitive User Interface. reNgine makes it easy for penetration testers to gather reconnaissance with minimal configuration and with the help of reNgine's correlation, it just makes recon effortless.