CVE-2025-34300
Unknown
Unknown - Not Provided
BaseFortify
Publication date: 2025-07-16
Last updated on: 2025-11-04
Assigner: VulnCheck
Description
Description
A template injection vulnerability exists in Sawtooth Software’s Lighthouse Studio versions prior to 9.16.14 via the ciwweb.pl http://ciwweb.pl/ Perl web application. Exploitation allows an unauthenticated attacker can execute arbitrary commands.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| sawtooth_software | lighthouse_studio | 9.16.14 |
| sawtooth_software | lighthouse_studio | * |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-1336 | The product uses a template engine to insert or process externally-influenced input, but it does not neutralize or incorrectly neutralizes special elements or syntax that can be interpreted as template expressions or other code directives when processed by the engine. |
| CWE-20 | The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability is a template injection flaw in Sawtooth Software's Lighthouse Studio versions before 9.16.14, specifically in the ciwweb.pl Perl web application. It allows an unauthenticated attacker to execute arbitrary commands on the affected system.
How can this vulnerability impact me? :
Exploitation of this vulnerability can lead to an attacker executing arbitrary commands without authentication, potentially compromising the affected system's security, leading to data breaches, system control loss, or further attacks.
Ask Our AI Assistant
Need more information? Ask your question to get an AI reply (Powered by our expertise)
0/70