VulnerabilityAnalyzed
CVE-2025-46545
In Sherpa Orchestrator 141851, the functionality for adding or updating licenses allows for stored XSS attacks by an administrator through the name parameter.
MEDIUM 4.8EPSS 0.27%
Does this matter?
Lower severity and a low EPSS score (0.27%). Track it; it rarely justifies an emergency change on its own.
Description
In Sherpa Orchestrator 141851, the functionality for adding or updating licenses allows for stored XSS attacks by an administrator through the name parameter. The XSS payload can execute when the license expires.
- CVSS 3.1
- 4.8 MEDIUMCVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 0.27% probability · 19th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- sherparpa/sherpa orchestrator
- Source
- cve@mitre.org
References
- https://deiteriy.comNot Applicable
- https://gist.github.com/ArtemBrylev/5a0c76285d5fa9daf4ec753034185de7Third Party Advisory
- https://sherparpa.comProduct
- https://twitter.com/ArtyomBrylevNot Applicable
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.