Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-59945

Опубликовано: 27 сент. 2025
Источник: nvd
CVSS3: 8.1
EPSS Низкий

Описание

SysReptor is a fully customizable pentest reporting platform. In versions from 2024.74 to before 2025.83, authenticated and unprivileged (non-admin) users can assign the is_project_admin permission to their own user. This allows users to read, modify and delete pentesting projects they are not members of and are therefore not supposed to access. This issue has been patched in version 2025.83.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:syslifters:sysreptor:*:*:*:*:*:*:*:*
Версия от 2024.74 (включая) до 2025.83 (исключая)

EPSS

Процентиль: 14%
0.00044
Низкий

8.1 High

CVSS3

Дефекты

CWE-266

EPSS

Процентиль: 14%
0.00044
Низкий

8.1 High

CVSS3

Дефекты

CWE-266