High severity8.8NVD Advisory· Published May 19, 2024· Updated Jun 17, 2026
CVE-2024-36076
CVE-2024-36076
Description
Cross-Site WebSocket Hijacking in SysReptor from version 2024.28 to version 2024.30 causes attackers to escalate privileges and obtain sensitive information when a logged-in SysReptor user visits a malicious same-site subdomain in the same browser session.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
32024.28 - 2024.30+ 1 more
- (no CPE)range: 2024.28 - 2024.30
- cpe:2.3:a:syslifters:sysreptor:*:*:*:*:*:*:*:*range: >=2024.28,<2024.40
Patches
Vulnerability mechanics
References
2- github.com/Syslifters/sysreptor/security/advisories/GHSA-2vfc-3h43-vghhnvdVendor Advisory
- github.com/Syslifters/sysreptor/releases/tag/2024.40nvdRelease Notes
News mentions
0No linked articles in our index yet.