SysReptor is a fully customizable pentest reporting platform. In versions from 2024.74 to before 2025.83, authenticated and unprivileged (non-admin) users can assign the is_project_admin permission to their own user. This allows users to read, modify and delete pentesting projects they are not members of and are therefore not supposed to access. This issue has been patched in version 2025.83.
Metrics
Affected Vendors & Products
References
History
Mon, 29 Sep 2025 14:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Mon, 29 Sep 2025 09:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Syslifters
Syslifters sysreptor |
|
Vendors & Products |
Syslifters
Syslifters sysreptor |
Sat, 27 Sep 2025 01:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | SysReptor is a fully customizable pentest reporting platform. In versions from 2024.74 to before 2025.83, authenticated and unprivileged (non-admin) users can assign the is_project_admin permission to their own user. This allows users to read, modify and delete pentesting projects they are not members of and are therefore not supposed to access. This issue has been patched in version 2025.83. | |
Title | SysReptor Susceptible to Privilege Escalation by Authenticated Users | |
Weaknesses | CWE-266 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: GitHub_M
Published: 2025-09-27T01:01:52.330Z
Updated: 2025-09-29T14:10:54.427Z
Reserved: 2025-09-23T14:33:49.506Z
Link: CVE-2025-59945

Updated: 2025-09-29T14:10:46.795Z

Status : Awaiting Analysis
Published: 2025-09-27T01:15:44.073
Modified: 2025-09-29T19:34:10.030
Link: CVE-2025-59945

No data.