Impact
The vulnerability originates from an oversight in the report template swap endpoint, which does not validate that a template belongs to the client requesting the swap, a weakness associated with CWE-639. This allows a client that can authenticate to the system to attach templates created by another client to its own reports, and then generate those reports to reveal the contents of the foreign templates, including letterhead, boilerplate, and methodology text. The primary impact is the unauthorized disclosure of confidential template data that may be used for competitive intelligence or further attacks, but it does not provide code execution or direct system compromise.
Affected Systems
The affected application is GhostManager Ghostwriter, specifically all releases prior to version 7.1.2 (the latest patching release, such as 7.1.1, still contains the flaw). No other variants or products are listed as impacted.
Risk and Exploitability
The CVSS score of 7.1 marks this as a high‑severity information‑disclosure risk. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. Attackers must first authenticate to the system, which means the risk is limited to compromised or shared credentials. Once authenticated, the attacker can enumerate template primary keys sequentially to discover foreign templates and then swap them in to view their contents. The lack of an automated exploit makes the immediate threat lower than some high‑severity flaws, yet the confidentiality impact justifies prompt remediation.
OpenCVE Enrichment