Impact
SysReptor, a customizable pentest reporting platform, does not rotate the session identifier after a user authenticates to a password‑protected shared note. This omission permits an attacker who has obtained an unauthenticated session cookie to force a victim to reuse that cookie after they enter the correct password, thereby gaining unauthorized access to the shared note. The flaw is limited to the shared‑note authentication flow; the main website login remains unaffected.
Affected Systems
System users running Syslifters SysReptor versions before 2026.68 are impacted. The vulnerability applies to any release prior to the 2026.68 update, regardless of other configuration settings.
Risk and Exploitability
The CVSS score is 3.7, indicating a low severity. The EPSS score is not available, so the likelihood of exploitation is currently unknown; however, once the vulnerability is known it could be abused if an attacker can capture an unauthenticated session cookie and know the shared‑note URL. The issue is not listed in CISA’s Known Exploited Vulnerabilities catalog. Based on the description, the most likely attack vector would involve an attacker delivering a crafted cookie to a victim and then directing the victim to access the shared note, after which the attacker can use the same session to read the content.
OpenCVE Enrichment