Cross-Site WebSocket Hijacking in SysReptor from version 2024.28 to version 2024.30 causes attackers to escalate privileges and obtain sensitive information when a logged-in SysReptor user visits a malicious same-site subdomain in the same browser session.
| Software | From | Fixed in |
|---|---|---|
| syslifters / sysreptor | 2024.28 | 2024.40 |