CVE-2023-50094 is an OS command injection vulnerability in reNgine before version 2.1.2. According to the provided content, an attacker with a valid session ID can inject shell metacharacters into the url parameter of the api/tools/waf_detector/ endpoint (i.e., api/tools/waf_detector/?url=). The application passes attacker-controlled input to subprocess.check_output, resulting in command execution on the underlying operating system. The supplied content further states that the injected commands are executed as root.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
api/tools/waf_detector/ endpoint. Apply least-privilege controls so the application does not run as root, and use input validation or allowlisting for URL parameters to reduce command injection risk. Network segmentation and monitoring for suspicious subprocess execution may also reduce exposure.Patch, then assume compromise.
api/tools/waf_detector/ endpoint is not passed to shell-interpreted command execution paths, and review any code paths using subprocess.check_output with untrusted input.1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository contains a proof-of-concept exploit for a command injection vulnerability (CVE-2023-50094) in reNgine v2.2.0. The exploit is implemented in a single Python script (poc.py) and is accompanied by a README.md with usage instructions and vulnerability details. The script authenticates to the target reNgine instance using provided credentials, then exploits the vulnerability by injecting a malicious payload into the 'nmap_cmd' parameter of a Scan Engine via the API. The payload is a base64-encoded Python reverse shell that connects back to 10.244.150.69:61612. The exploit requires valid credentials and knowledge of the Scan Engine ID. The repository is structured simply, with the main exploit logic in poc.py and documentation in README.md. No framework is used; the exploit is standalone and operational, providing remote code execution capabilities to an authenticated attacker.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Specific vulnerability referenced in a repository update/PR context; no technical details about the flaw are provided in the content.
Referenced only as a nuclei template whose CPE format was corrected by filling the empty product field with 'rengine'.
Specific vulnerability template referenced in a nuclei-templates pull request for CPE format correction.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.