Descrição
SysReptor is a fully customizable pentest reporting platform. Prior to version 2026.29, users with -User Admin- permissions can change the email addresses of users with -Superuser- permissions. If the SysReptor installation has the -Forgot Password- functionality enabled (non-default), they can reset the Superusers- passwords and authenticate, if the Superuser has no MFA enabled. User managers can then access the Django backend (/admin) or manipulate the settings of the SysReptor installation. Note that user managers have the ability to access all pentest projects by assigning themselves -Project Admin- permissions. This is intentional and by design. This issue has been patched in version 2026.29.
CVSS 3.8EPSS 0.16199999999999998%Risco 0.39
Ver fonte- Publicação
- 2026-05-08 23:16:39
- Versões afetadas
- <2026.29
- Tipo
- Core software
- Última alteração
- 2026-07-24 20:10:00
- Vetor
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N