CVE-2025-66561: SysReptor Vulnerable to an Authenticated Stored Cross-Site Scripting (XSS)
SysReptor is a fully customizable pentest reporting platform. Prior to 2025.102, there is a Stored Cross-Site Scripting (XSS) vulnerability allows authenticated users to execute malicious JavaScript in the context of other logged-in users by uploading malicious JavaScript files in the web UI. This vulnerability is fixed in 2025.102.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-66561?
CVE-2025-66561 is considered to have a high severity due to its potential for executing malicious JavaScript in the context of other users.
How do I fix CVE-2025-66561?
To fix CVE-2025-66561, upgrade SysReptor to version 2025.102 or later to eliminate the stored Cross-Site Scripting vulnerability.
Who is affected by CVE-2025-66561?
Authenticated users of SysReptor versions prior to 2025.102 are affected by CVE-2025-66561.
What kind of attack is possible with CVE-2025-66561?
CVE-2025-66561 allows for stored Cross-Site Scripting attacks where attackers can run malicious scripts on the browsers of other logged-in users.
Is user authentication required to exploit CVE-2025-66561?
Yes, exploitation of CVE-2025-66561 requires user authentication to upload malicious JavaScript files.