Skip to main content

CVE-2025-34300: CWE-20 Improper Input Validation in Sawtooth Software Lighthouse Studio

Critical
VulnerabilityCVE-2025-34300cvecve-2025-34300cwe-20cwe-1336
Published: Wed Jul 16 2025 (07/16/2025, 12:57:27 UTC)
Source: CVE Database V5
Vendor/Project: Sawtooth Software
Product: Lighthouse Studio

Description

A template injection vulnerability exists in Sawtooth Software’s Lighthouse Studio versions prior to 9.16.14 via the  ciwweb.pl http://ciwweb.pl/  Perl web application. Exploitation allows an unauthenticated attacker can execute arbitrary commands.

Technical Details

Data Version
5.1
Assigner Short Name
VulnCheck
Date Reserved
2025-04-15T19:15:22.582Z
Cvss Version
4.0
State
PUBLISHED

Threat ID: 6877a61aa83201eaacdb3fd8

Added to database: 7/16/2025, 1:16:10 PM

Last updated: 7/16/2025, 1:16:10 PM

Views: 1

Actions

Please log in to the Console to use AI analysis features.

Need enhanced features?

Contact root@offseq.com for Pro access with improved analysis and higher rate limits.

Latest Threats