CVE-2022-36566: OS Command Injection
Published Aug 31, 2022
·Updated
Rengine v1.3.0 was discovered to contain a command injection vulnerability via the scan engine function.
Affected Software
2 affected components
Yogeshojha Rengine=1.3.0
Rengine Project Rengine=1.3.0
Event History
Aug 31, 2022
CVE Published
via MITRE·05:12 PM
Data Sourced
via MITRE·05:12 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2022-36566?
CVE-2022-36566 is classified as a critical command injection vulnerability.
2
How do I fix CVE-2022-36566?
To fix CVE-2022-36566, update Rengine to the latest version where the vulnerability has been patched.
3
What are the consequences of exploiting CVE-2022-36566?
Exploitation of CVE-2022-36566 could allow an attacker to execute arbitrary commands on the server.
4
Which versions are affected by CVE-2022-36566?
CVE-2022-36566 affects Rengine version 1.3.0 from both Yogeshojha and Rengine Project.
5
Is CVE-2022-36566 easy to exploit?
Yes, CVE-2022-36566 can be relatively easy to exploit, making it critical for users to apply mitigations.