Vulnerabilities (CVE)

Filtered by vendor Yogeshojha Subscribe
Filtered by product Rengine
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-50094 1 Yogeshojha 1 Rengine 2024-01-09 N/A 8.8 HIGH
reNgine through 2.0.2 allows OS Command Injection if an adversary has a valid session ID. The attack places shell metacharacters in an api/tools/waf_detector/?url= string. The commands are executed as root via subprocess.check_output.