A template injection vulnerability exists in Sawtooth Software’s Lighthouse Studio versions prior to 9.16.14 via the ciwweb.pl http://ciwweb.pl/ Perl web application. Exploitation allows an unauthenticated attacker can execute arbitrary commands.CreditsAdam Kues - AssetnoteReferenceshttps://sawtoothsoftware.com/resources/software-downloads/lighthouse-studio/version-historyhttps://slcyber.io/assetnote-security-research-center/rce-in-the-most-popular-survey-software-youve-never-heard-of/https://www.vulncheck.com/advisories/sawtooth-software-lighthouse-studio-preauthentication-rce