Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2025-46547


In Sherpa Orchestrator 141851, the web application lacks protection against CSRF attacks, with resultant effects of an attacker conducting XSS attacks, adding a new user or role, or exploiting a SQL injection issue.


Published

2025-04-25T03:15:20.430

Last Modified

2025-10-16T20:33:34.913

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 5.4 (MEDIUM)

Weaknesses
  • Type: Secondary
    CWE-352

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application sherparpa sherpa_orchestrator 141851 Yes

References