← Zurück zur CVE-Suche

CVE-2026-44987

SysReptor

Beschreibung

SysReptor is a fully customizable pentest reporting platform. Prior to version 2026.29, users with -User Admin- permissions can change the email addresses of users with -Superuser- permissions. If the SysReptor installation has the -Forgot Password- functionality enabled (non-default), they can reset the Superusers- passwords and authenticate, if the Superuser has no MFA enabled. User managers can then access the Django backend (/admin) or manipulate the settings of the SysReptor installation. Note that user managers have the ability to access all pentest projects by assigning themselves -Project Admin- permissions. This is intentional and by design. This issue has been patched in version 2026.29.

CVSS 3.8EPSS 0.16199999999999998%Risiko 0.39
Quelle öffnen
Veröffentlicht
2026-05-08 23:16:39
Betroffene Versionen
<2026.29
Typ
Core software
Zuletzt geändert
2026-07-24 20:10:00
Vektor
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N