ZeroHour

CVE-2025-34300

niche

Template Injection Yields Unauthenticated RCE in Sawtooth Lighthouse Studio

CVSS 4.0
10.0 critical
EPSS
78%p100
Published
()
Modified
AI analysis

CVE-2025-34300 is a template injection flaw (CWE-1336, with related improper input validation CWE-20) in the ciwweb.pl Perl web application used by Sawtooth Software's Lighthouse Studio survey platform. An unauthenticated remote attacker can submit crafted input that is processed as a template by ciwweb.pl, causing the server to evaluate and execute attacker-controlled commands. Successful exploitation yields full remote code execution on the hosting web server, with high impact on confidentiality, integrity, and availability reflected in the maximum CVSS 4.0 score of 10. Any organization running Lighthouse Studio versions prior to 9.16.14 with the ciwweb.pl survey application exposed via the web is affected. Exploitation has not yet been confirmed in the wild (no KEV listing, no public PoC), but the EPSS score of 78.1% (100th percentile) indicates a very high likelihood of exploitation within the next 30 days.

What to do: Upgrade Sawtooth Software Lighthouse Studio to version 9.16.14 or later. If upgrading is not immediately possible, restrict network access to the server hosting ciwweb.pl (e.g., allow only trusted clients or place it behind a VPN/WAF) and monitor web logs for suspicious command execution activity. Given the very high EPSS score, prioritize patching internet-facing survey hosting servers first.

Affected
Sawtooth Software Lighthouse Studio (ciwweb.pl Perl web application)All versions prior to 9.16.14
Estimated exposure
nichelikely hundreds to a few thousand internet-exposed survey hosting servers running ciwweb.pl (no public scan counts available) — Lighthouse Studio is specialized market-research survey software typically deployed by research firms and dedicated survey-hosting web servers, a comparatively small installed base; no active-install or internet-scan figures were provided…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A template injection vulnerability exists in Sawtooth Software’s Lighthouse Studio versions prior to 9.16.14 via the ciwweb.pl http://ciwweb.pl/ Perl web application. Exploitation allows an unauthenticated attacker can execute arbitrary commands.

Weakness
CWE-20, CWE-1336
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news