PT-2026-79796 · Unknown · Ghostwriter
CVSS v3.1
7.1
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Ghostwriter versions prior to 7.1.2
Description
Ghostwriter fails to validate template ownership in the report template swap endpoint. This allows attackers to attach client-scoped templates belonging to other clients to their own reports by exploiting sequential template primary keys to enumerate and attach foreign templates. Consequently, attackers can generate reports to disclose sensitive template contents, such as letterhead, boilerplate, and methodology text.
Recommendations
Update Ghostwriter to version 7.1.2 or later.
Exploit
Fix
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ghostwriter