PT-2025-17869 · Unknown · Sherpa Orchestrator
Artem Brylev
·
Published
2025-04-25
·
Updated
2025-10-16
·
CVE-2025-46547
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Sherpa Orchestrator version 141851
Description
The web application lacks protection against CSRF attacks, allowing an attacker to conduct XSS attacks, add a new user or role, or exploit a SQL injection issue.
Recommendations
For Sherpa Orchestrator version 141851, consider implementing protection against CSRF attacks to prevent exploitation.
As a temporary workaround, restrict access to sensitive features that could be exploited through CSRF attacks, such as user or role management.
Avoid using the web application for sensitive operations until the CSRF protection issue is resolved.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sherpa Orchestrator