An issue in OpenKnowledgeMaps Headstart v7 allows a remote attacker to escalate privileges via the url parameter of the getPDF.php component
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.