← Back
Web Application
CVE-2026-78203 high CVSS 7.1

Ghostwriter before 7.1.2 fails to validate template ownership in the report template swap...

Summary

Ghostwriter before 7.1.2 fails to validate template ownership in the report template swap...

AI summary openai / gpt-4o

Ghostwriterのバージョン7.1.2より前では、レポートテンプレートの所有権が適切に検証されていないため、攻撃者が他のクライアントのテンプレートを自身のレポートに付加できる脆弱性があります。これにより、テンプレートの内容(ヘッダーや標準文など)が漏洩する可能性があります。この問題は、テンプレートの一意のキーを利用して発生します。
❓ What is the problem
Ghostwriterにおけるレポートテンプレートの所有権検証不備による情報漏洩の脆弱性。
📍 Affected scope
Ghostwriterのバージョン7.1.2より前のバージョン。
🔥 Severity
テンプレートの非許可な付加と内容漏洩が可能であり、機密情報が流出する恐れがあるため重要。
🔧 How to fix
バージョン7.1.2 以上へのアップグレードを推奨。
🛡️ Workaround
情報なし。
🔍 Detection
テンプレートキーを確認し、非許可のテンプレートが使用されていないかを確認する。

References

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →