CVE-2025-59945
SysReptor Susceptible to Privilege Escalation by Authenticated Users
Vexday Risk Score
21Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 8.1EPSS 0.3%KEV nãoPoC —Nuclei —Metasploit —Patch —
Lifecycle
27 Sep 2025Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
SysReptor is a fully customizable pentest reporting platform. In versions from 2024.74 to before 2025.83, authenticated and unprivileged (non-admin) users can assign the is_project_admin permission to their own user. This allows users to read, modify and delete pentesting projects they are not members of and are therefore not supposed to access. This issue has been patched in version 2025.83.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Affected products
Syslifters · sysreptorWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →