CVE-2024-36076
19.05.2024, 20:15
Cross-Site WebSocket Hijacking in SysReptor from version 2024.28 to version 2024.30 causes attackers to escalate privileges and obtain sensitive information when a logged-in SysReptor user visits a malicious same-site subdomain in the same browser session.
| Vendor | Product | Version |
|---|---|---|
| syslifters | sysreptor | 2024.28 ≤ 𝑥 < 2024.40 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration