CVE-2024-36076: Syslifters Sysreptor
High severity, CVSS 8.8. EPSS: 0.2% chance of exploitation in the next 30 days.
Cross-Site WebSocket Hijacking in SysReptor from version 2024.28 to version 2024.30 causes attackers to escalate privileges and obtain sensitive information when a logged-in SysReptor user visits a malicious same-site subdomain in the same browser session.
Affected products
- Syslifters Sysreptor: from 2024.28, before 2024.40 (fixed in 2024.40)
Published 2024-05-19. Last modified 2026-06-17.