SysReptor Privilege Escalation Vulnerability Allowing Unauthorized Project Access

Vulnerability

A vulnerability in SysReptor, a customizable pentest reporting platform, allows authenticated and unprivileged users to grant themselves the 'is_project_admin' permission in versions 2024.74 prior to 2025.83. This unauthorized permission assignment enables users to read, modify, and delete pentesting projects they do not belong to, violating access controls. The vulnerability has been patched in version 2025.83.

Impact

Exploitation of this vulnerability allows for unauthorized access to pentesting projects, enabling users to read, modify, and delete projects they are not supposed to access.

Remediation

Users can update to SysReptor version 2025.83 to address this vulnerability. For those using SysReptor cloud installations, the update has already been applied.

Added: Sep 27, 2025, 1:17 AM
Updated: Sep 27, 2025, 1:17 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
5.0
exploitability
5.9
remediation
7.7
relevance
0.6
threat
3.2
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.