CVE-2025-34300
Unknown Unknown - Not Provided
BaseFortify

Publication date: 2025-07-16

Last updated on: 2025-11-04

Assigner: VulnCheck

Description
A template injection vulnerability exists in Sawtooth Software’s Lighthouse Studio versions prior to 9.16.14 via the  ciwweb.pl http://ciwweb.pl/  Perl web application. Exploitation allows an unauthenticated attacker can execute arbitrary commands.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2025-07-16
Last Modified
2025-11-04
Generated
2026-05-09
AI Q&A
2025-07-16
EPSS Evaluated
2026-05-08
NVD
Affected Vendors & Products
Showing 2 associated CPEs
Vendor Product Version / Range
sawtooth_software lighthouse_studio 9.16.14
sawtooth_software lighthouse_studio *
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-1336 The product uses a template engine to insert or process externally-influenced input, but it does not neutralize or incorrectly neutralizes special elements or syntax that can be interpreted as template expressions or other code directives when processed by the engine.
CWE-20 The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?

This vulnerability is a template injection flaw in Sawtooth Software's Lighthouse Studio versions before 9.16.14, specifically in the ciwweb.pl Perl web application. It allows an unauthenticated attacker to execute arbitrary commands on the affected system.


How can this vulnerability impact me? :

Exploitation of this vulnerability can lead to an attacker executing arbitrary commands without authentication, potentially compromising the affected system's security, leading to data breaches, system control loss, or further attacks.


Ask Our AI Assistant
Need more information? Ask your question to get an AI reply (Powered by our expertise)
0/70
EPSS Chart