Vendor
Ghostwriter versions prior to 7.1.2 are vulnerable to an authorization bypass via the report template swap endpoint, allowing authenticated attackers to enumerate and exfiltrate sensitive client-scoped template contents.