CVE-2024-36076: Syslifters Sysreptor

High severity, CVSS 8.8. EPSS: 0.2% chance of exploitation in the next 30 days.

Cross-Site WebSocket Hijacking in SysReptor from version 2024.28 to version 2024.30 causes attackers to escalate privileges and obtain sensitive information when a logged-in SysReptor user visits a malicious same-site subdomain in the same browser session.

Affected products

  • Syslifters Sysreptor: from 2024.28, before 2024.40 (fixed in 2024.40)

Published 2024-05-19. Last modified 2026-06-17.