← Back to browse · API

CVE-2023-50094

Severity
HIGH
CVSS
8.8
EPSS
0.1354
Risk score
39.94
CISA KEV
No
PoC
No
Published
2024-01-01
Modified
2025-04-17
First seen
2026-08-07
Aliases
EUVD-2023-54924, GHSA-VFHC-4Q79-WVF9
Products
n/a:n/a n/a
Sources
euvd EUVD-2023-54924

Description

reNgine before 2.1.2 allows OS Command Injection if an adversary has a valid session ID. The attack places shell metacharacters in an api/tools/waf_detector/?url= string. The commands are executed as root via subprocess.check_output.

References