SysReptor is a fully customizable pentest reporting platform. Prior to 2026.68, an unauthenticated attacker who holds a public read-write note share link can disclose an uploaded file or image from the same project by updating the shared note to reference the
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Syslifters | sysreptor | < 2026.68 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Syslifters | sysreptor | < 2026.68 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-81180 | 8.8 HIGH | SysReptor: Authenticated RCE by insecure image processing |
| CVE-2026-81179 | 8.1 HIGH | SysReptor: Host header injection might allow account takeover |
| CVE-2026-81181 | 3.7 LOW | SysReptor: Session Fixation in Password-Protected Shared Notes |
| CVE-2026-81178 | 3.5 LOW | SysReptor: Anonymous note-share link discloses project member identities and non-shared no |
No comments yet