← Back

CVE-2025-61319

nvd nist
Published: Oct 10, 2025Modified: Jun 17, 2026

JSON object

Loading...
6.1
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Exploitability: 2.8 / Impact: 2.7
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0 (Secondary)

Description

ReNgine thru 2.2.0 is vulnerable to a Stored Cross-Site Scripting (XSS) vulnerability in the Vulnerabilities module. When scanning a target with an XSS payload, the unsanitized payload is rendered in the ReNgine web UI, resulting in arbitrary JavaScript execution in the victim's browser. This can be abused to steal session cookies, perform unauthorized actions, or compromise the ReNgine administrator's account.

Affected (1)

Products: Yogeshojha: Rengine
1 product
Rengine
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Up to 2.2.0

References (2)

Source: cve@mitre.org
ExploitThird Party Advisory
Source: cve@mitre.org
Product

Timeline

No history available yet.