PT-2025-49172 · Sysreptor · Sysreptor

Published

2025-12-04

·

Updated

2025-12-11

·

CVE-2025-66561

CVSS v3.1

7.3

High

VectorAV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions SysReptor versions prior to 2025.102
Description A Stored Cross-Site Scripting (XSS) issue exists in SysReptor, a customizable pentest reporting platform. Authenticated users can execute malicious JavaScript code within the context of other logged-in users. This is achieved by uploading malicious JavaScript files through the web user interface.
Recommendations Update to version 2025.102 or later.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2025-66561
GHSA-64VW-V5C4-MGVM

Affected Products

Sysreptor