CVE-2023-50094

Severity CVSS v4.0:
Pending analysis
Type:
CWE-78 OS Command Injections
Publication date:
01/01/2024
Last modified:
17/04/2025

Description

reNgine before 2.1.2 allows OS Command Injection if an adversary has a valid session ID. The attack places shell metacharacters in an api/tools/waf_detector/?url= string. The commands are executed as root via subprocess.check_output.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:yogeshojha:rengine:*:*:*:*:*:*:*:* 2.0.2 (including)