CVE-2025-59945: SysReptor Susceptible to Privilege Escalation by Authenticated Users
SysReptor is a fully customizable pentest reporting platform. In versions from 2024.74 to before 2025.83, authenticated and unprivileged (non-admin) users can assign the isprojectadmin permission to their own user. This allows users to read, modify and delete pentesting projects they are not members of and are therefore not supposed to access. This issue has been patched in version 2025.83.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2025-59945?
CVE-2025-59945 is considered a high severity vulnerability due to unauthorized privilege escalation capabilities.
How do I fix CVE-2025-59945?
To fix CVE-2025-59945, upgrade SysReptor to version 2025.83 or later.
Who is affected by CVE-2025-59945?
Authenticated and unprivileged (non-admin) users of SysReptor versions 2024.74 to before 2025.83 are affected by CVE-2025-59945.
What actions can be performed by exploiting CVE-2025-59945?
Exploiting CVE-2025-59945 allows users to read, modify, and delete pentesting projects without appropriate permissions.
When was CVE-2025-59945 discovered?
CVE-2025-59945 was reported following the release of SysReptor versions 2024.74 to before 2025.83.