VulnerabilityAnalyzed
CVE-2025-46547
In Sherpa Orchestrator 141851, the web application lacks protection against CSRF attacks, with resultant effects of an attacker conducting XSS attacks, adding a new user or role, or exploiting a SQL injection issue.
MEDIUM 6.1EPSS 0.16%
Does this matter?
Lower severity and a low EPSS score (0.16%). Track it; it rarely justifies an emergency change on its own.
Description
In Sherpa Orchestrator 141851, the web application lacks protection against CSRF attacks, with resultant effects of an attacker conducting XSS attacks, adding a new user or role, or exploiting a SQL injection issue.
- CVSS 3.1
- 6.1 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 0.16% probability · 6th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-352
- Affected
- sherparpa/sherpa orchestrator
- Source
- cve@mitre.org
References
- https://deiteriy.comNot Applicable
- https://gist.github.com/ArtemBrylev/9af206c46d7505db03ad6fcd9fc46f7fThird Party Advisory
- https://sherparpa.comProduct
- https://twitter.com/ArtyomBrylevNot Applicable
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.