Description


Gophish through 0.12.1 contains an insecure direct object reference vulnerability that allows authenticated users to take over other users' groups, templates, landing pages and sending profiles. Attackers can supply another user's sequential id in POST requests to /api/groups/, /api/templates/, /api/pages/ or /api/smtp/ to overwrite and reassign objects, locking out owners and exposing victims' recipient lists.

Related CPE's


Could not find any relations

Weaknesses



CWE-639

CVSS impact metrics


CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N

7.1 · High

Information


Source identifier

[email protected]

Vulnerability status

Deferred

Published

2026-10-07T16:17:46.490Z

40 hours ago

Last modified

2026-10-07T17:16:54.063Z

39 hours ago