« Volver al listado

Syslifters

Syslifters Sysreptor: vulnerabilidades y CVE

Syslifters Sysreptor tiene 10 vulnerabilidades publicadas, 8 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE10
Últimos 12 meses8
Críticas0
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-81182Media (4.2)0.27%—18 sept 2026
SysReptor is a fully customizable pentest reporting platform. Prior to 2026.68, an unauthenticated attacker who holds a public read-write note share link can disclose an uploaded file or image from the same project by…
CVE-2026-81181Baja (3.7)0.28%—18 sept 2026
SysReptor is a fully customizable pentest reporting platform. Prior to 2026.68, the password authentication flow for protected shared notes does not rotate the session identifier after successful authentication,…
CVE-2026-81180Alta (8.8)0.66%—18 sept 2026
SysReptor is a fully customizable pentest reporting platform. Prior to 2026.61, authenticated users of SysReptor Professional can upload image files whose formats cause image processing to invoke Ghostscript, allowing…
CVE-2026-81179Alta (8.1)0.48%—18 sept 2026
SysReptor is a fully customizable pentest reporting platform. Prior to 2026.58, installations that enable password reset by email while configuring ALLOWED_HOSTS with a wildcard accept an attacker-controlled Host header…
CVE-2026-81178Baja (3.5)0.30%—18 sept 2026
SysReptor is a fully customizable pentest reporting platform. Prior to 2026.55, an unauthenticated holder of a public note share link receives project-wide collaborative editing metadata because the public share…
CVE-2026-44987Baja (3.8)0.27%—8 may 2026
SysReptor is a fully customizable pentest reporting platform. Prior to version 2026.29, users with "User Admin" permissions can change the email addresses of users with "Superuser" permissions. If the SysReptor…
CVE-2026-42291Media (6.8)0.31%—8 may 2026
SysReptor is a fully customizable pentest reporting platform. From version 2026.4 to before version 2026.27, the endpoints for reading and creating sharing links for personal notes is not properly authorized. This…
CVE-2025-66561Media (5.4)0.19%—4 dic 2025
SysReptor is a fully customizable pentest reporting platform. Prior to 2025.102, there is a Stored Cross-Site Scripting (XSS) vulnerability allows authenticated users to execute malicious JavaScript in the context of…
CVE-2025-59945Alta (8.1)0.33%—27 sept 2025
SysReptor is a fully customizable pentest reporting platform. In versions from 2024.74 to before 2025.83, authenticated and unprivileged (non-admin) users can assign the is_project_admin permission to their own user.…
CVE-2024-36076Alta (8.8)0.25%—19 may 2024
Cross-Site WebSocket Hijacking in SysReptor from version 2024.28 to version 2024.30 causes attackers to escalate privileges and obtain sensitive information when a logged-in SysReptor user visits a malicious same-site…

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1203 Exploitation for Client Execution3
  2. T1210 Exploitation of Remote Services3
  3. T1078 Valid Accounts2
  4. T1005 Data from Local System1
  5. T1059.007 JavaScript1
  6. T1078.001 Default Accounts1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.