Skip to main content
Vulnerability Database/CVE-2025-66561

CVE-2025-66561: Syslifters Sysreptor Stored XSS Vulnerability

CVE-2025-66561 is a stored XSS vulnerability in Syslifters Sysreptor that allows authenticated users to execute malicious JavaScript by uploading files. This article covers the technical details, affected versions, and mitigation.

Published:

CVE-2025-66561 Overview

CVE-2025-66561 is a Stored Cross-Site Scripting (XSS) vulnerability in SysReptor, a customizable pentest reporting platform developed by Syslifters. The flaw affects all versions prior to 2025.102 and allows authenticated users to upload malicious JavaScript files through the web UI. When other logged-in users interact with the uploaded content, the injected script executes in their browser session. The vulnerability is tracked under CWE-79 and is fixed in release 2025.102.

Critical Impact

An authenticated attacker can execute arbitrary JavaScript in the context of other logged-in SysReptor users, enabling session hijacking, data theft, or unauthorized actions on the platform.

Affected Products

  • Syslifters SysReptor versions prior to 2025.102
  • All deployments where authenticated users can upload files through the web UI
  • Self-hosted and cloud SysReptor instances running vulnerable builds

Discovery Timeline

  • 2025-12-04 - CVE-2025-66561 published to NVD
  • 2026-06-17 - Last updated in NVD database

Technical Details for CVE-2025-66561

Vulnerability Analysis

SysReptor is a collaborative pentest reporting platform where users upload evidence, screenshots, and supporting files as part of engagement reporting. The vulnerability stems from insufficient sanitization of uploaded JavaScript files served back through the web UI. An authenticated user with permission to upload files can store a payload that later executes in the browser of any user who accesses the file. Because the payload runs within the authenticated origin, it inherits the victim's session context and privileges.

The scope-changed impact reflected in the CVSS vector indicates that the injected script can affect resources beyond the vulnerable component itself. Consequences include exfiltration of report data, theft of session tokens, forced actions on behalf of the victim, and lateral movement across pentest projects shared by multiple team members.

Root Cause

The root cause is improper handling of file content types or missing Content Security Policy (CSP) enforcement when serving user-uploaded files. Uploaded JavaScript is rendered or executed by the browser instead of being served as inert attachments. The fix in version 2025.102 addresses the unsafe file-serving behavior.

Attack Vector

Exploitation requires an authenticated account with upload privileges and user interaction from a victim (a logged-in user must open the malicious file). The attack is delivered over the network against the SysReptor web interface. No exploit code is publicly available at the time of publication, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. Refer to the GitHub Security Advisory GHSA-64vw-v5c4-mgvm for vendor technical details.

Detection Methods for CVE-2025-66561

Indicators of Compromise

  • Uploaded files with .js, .html, .svg, or other browser-executable MIME types in SysReptor project attachments
  • Unusual outbound requests from analyst browsers to attacker-controlled domains shortly after opening report attachments
  • Unexpected session token usage from atypical geolocations or user agents following file access

Detection Strategies

  • Review SysReptor audit logs for file upload events, focusing on filenames and content types not typically used in report evidence
  • Inspect web proxy or browser telemetry for script executions originating from the SysReptor application domain
  • Correlate account activity spikes with file access events to identify potential post-exploitation actions

Monitoring Recommendations

  • Enable verbose logging on the SysReptor deployment and forward events to a central SIEM for retention and correlation
  • Monitor authentication anomalies for accounts that recently accessed uploaded attachments
  • Alert on new or modified files uploaded by accounts with low historical activity or recently created accounts

How to Mitigate CVE-2025-66561

Immediate Actions Required

  • Upgrade all SysReptor instances to version 2025.102 or later without delay
  • Audit user upload activity in versions prior to 2025.102 for suspicious JavaScript, HTML, or SVG files
  • Rotate session tokens and API keys for users who may have accessed malicious uploads
  • Review user permissions and remove upload rights from accounts that do not require them

Patch Information

Syslifters released a fix in SysReptor 2025.102. Upgrade instructions and release details are available in the GitHub Security Advisory GHSA-64vw-v5c4-mgvm. Self-hosted deployments should follow the standard upgrade procedure documented by the vendor.

Workarounds

  • Restrict upload permissions to trusted users only until the patch is applied
  • Deploy a reverse proxy rule to force a Content-Disposition: attachment header on downloaded files, preventing inline browser execution
  • Enforce a strict Content Security Policy (CSP) at the reverse proxy layer to block inline script execution from the application origin
bash
# Example nginx configuration to force attachment downloads and add CSP
location /api/v1/*/files/ {
    add_header Content-Disposition "attachment" always;
    add_header Content-Security-Policy "default-src 'none'; sandbox;" always;
    add_header X-Content-Type-Options "nosniff" always;
    proxy_pass http://sysreptor_backend;
}

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.