CVE Database
/

CVE-2025-24962

Back to search

CVE-2025-24962

Published: Feb 3, 2025

Modified: Feb 12, 2025

PUBLISHED

Description

reNgine is an automated reconnaissance framework for web applications. In affected versions a user can inject commands via the nmap_cmd parameters. This issue has been addressed in commit `c28e5c8d` and is expected in the next versioned release. Users are advised to filter user input and monitor the project for a new release.

VendorProductVersions

yogeshojha

rengine

affected
<= 2.2.0

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now