CVE-2025-34300
Severity CVSS v4.0:
CRITICAL
Type:
CWE-20
Input Validation
Publication date:
16/07/2025
Last modified:
04/11/2025
Description
A template injection vulnerability exists in Sawtooth Software’s Lighthouse Studio versions prior to 9.16.14 via the ciwweb.pl http://ciwweb.pl/ Perl web application. Exploitation allows an unauthenticated attacker can execute arbitrary commands.
Impact
Base Score 4.0
10.00
Severity 4.0
CRITICAL
References to Advisories, Solutions, and Tools
- https://sawtoothsoftware.com/resources/software-downloads/lighthouse-studio/version-history
- https://slcyber.io/assetnote-security-research-center/rce-in-the-most-popular-survey-software-youve-never-heard-of/
- https://www.vulncheck.com/advisories/sawtooth-software-lighthouse-studio-preauthentication-rce
- https://slcyber.io/assetnote-security-research-center/rce-in-the-most-popular-survey-software-youve-never-heard-of/



