PT-2025-49172 · Sysreptor · Sysreptor

CVE-2025-66561

·

Published

2025-12-04

·

Updated

2025-12-11

CVSS v3.1

7.3

High

VectorAV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions SysReptor versions prior to 2025.102
Description A Stored Cross-Site Scripting (XSS) issue exists in SysReptor, a customizable pentest reporting platform. Authenticated users can execute malicious JavaScript code within the context of other logged-in users. This is achieved by uploading malicious JavaScript files through the web user interface.
Recommendations Update to version 2025.102 or later.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-66561
GHSA-64VW-V5C4-MGVM

Affected Products

Sysreptor