CyberRota Analysis
This is a medium severity vulnerability with a CVSS score of 5.4. Public exploit code or proof-of-concept references have been detected in its references. It involves a SQL injection risk.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Detected Signals
exploit
GitHub PoC Links
Note: these links are listed for security research and verification purposes only.
CVE
CVE-2025-46547
Severity
MEDIUM
CVSS
5.4
EPSS
0.16%
Original NVD Description
In Sherpa Orchestrator 141851, the web application lacks protection against CSRF attacks, with resultant effects of an attacker conducting XSS attacks, adding a new user or role, or exploiting a SQL injection issue.
Related CVEs
Other vulnerabilities affecting the same vendor(s)