Description
A template injection vulnerability exists in Sawtooth Software’s Lighthouse Studio versions prior to 9.16.14 via the ciwweb.pl http://ciwweb.pl/ Perl web application. Exploitation allows an unauthenticated attacker can execute arbitrary commands.
Problem types
CWE-20 Improper Input Validation
CWE-1336 Improper Neutralization of Special Elements Used in a Template Engine
Product status
Any version before 9.16.14
Credits
Adam Kues - Assetnote
References
slcyber.io/...-popular-survey-software-youve-never-heard-of/
sawtoothsoftware.com/...ds/lighthouse-studio/version-history
slcyber.io/...-popular-survey-software-youve-never-heard-of/
www.vulncheck.com/...lighthouse-studio-preauthentication-rce