SysReptor is a fully customizable pentest reporting platform. Prior to 2026.68, the password authentication flow for protected shared notes does not rotate the session identifier after successful authentication, allowing session fixation. An attacker who can o
| 厂商 | 产品 | 版本范围 | 状态 |
|---|---|---|---|
| Syslifters | sysreptor | < 2026.68 |
affected |
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
| 厂商 | 产品 | 影响版本 | CPE | 订阅 |
|---|---|---|---|---|
| Syslifters | sysreptor | < 2026.68 | - |
|
| # | POC 描述 | 源链接 | 神龙链接 |
|---|
未找到公开 POC。
登录以生成 AI POC| CVE-2026-81180 | 8.8 HIGH | SysReptor 不安全图片处理致认证远程代码执行 |
| CVE-2026-81179 | 8.1 HIGH | SysReptor 主机头注入账户接管漏洞 |
| CVE-2026-81182 | 4.2 MEDIUM | SysReptor 共享笔记文件未授权披露漏洞 |
| CVE-2026-81178 | 3.5 LOW | SysReptor 笔记共享链接敏感信息泄露 |
暂无评论