Authenticated Remote Code Execution via Jinja2 in Ghostwriter <= v3.1.3
### Description It is possible for an authenticated user to craft, upload, and use a malicious Microsoft Word report template to achieve remote code execution (RCE) inside the _ghostwriter-djang...
github.com