We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.
Please see our statement on Data Privacy.
A template injection vulnerability exists in Sawtooth Software’s Lighthouse Studio versions prior to 9.16.14 via the ciwweb.pl http://ciwweb.pl/ Perl web application. Exploitation allows an unauthenticated attacker can execute arbitrary commands.
Reserved 2025-04-15 | Published 2025-07-16 | Updated 2025-07-16 | Assigner VulnCheckCWE-20 Improper Input Validation
CWE-1336 Improper Neutralization of Special Elements Used in a Template Engine
Adam Kues - Assetnote
sawtoothsoftware.com/...software-downloads/lighthouse-studio
slcyber.io/...-popular-survey-software-youve-never-heard-of/
Support options