CVE-2024-58287
reNgine 2.2.0 contains a command injection vulnerability in the nmapcmd parameter of scan engine configuration that allows authenticated attackers to execute arbitrary commands. Attackers can modify the nmapcmd parameter with malicious base64-encoded payloads to achieve remote code execution during scan engine configuration.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://rengine.wiki/, https://www.exploit-db.com/exploits/52081, https://www.vulncheck.com/advisories/rengine-authenticated-command-injection-via-scan-engine-configuration, https://github.com/yogeshojha/rengine
