In Sherpa Orchestrator 141851, multiple time-based blind SQL injections can be performed by an authenticated user. This affects api/gui/asset/list, /api/gui/files/export/csv/, /api/gui/files/list, /api/gui/process/export/csv, /api/gui/process/export/xlsx, /api/gui/process/listAll, /api/gui/processVersion/export/csv/, /api/gui/processVersion/export/xlsx/, /api/gui/processVersion/list/, /api/gui/robot/list/, /api/gui/task/export/csv/, /api/gui/task/export/xlsx/, and /api/gui/task/list/.
Metrics
Affected Vendors & Products
References
History
Thu, 16 Oct 2025 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Sherparpa
Sherparpa sherpa Orchestrator |
|
| CPEs | cpe:2.3:a:sherparpa:sherpa_orchestrator:141851:*:*:*:*:*:*:* | |
| Vendors & Products |
Sherparpa
Sherparpa sherpa Orchestrator |
Fri, 25 Apr 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 25 Apr 2025 03:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In Sherpa Orchestrator 141851, multiple time-based blind SQL injections can be performed by an authenticated user. This affects api/gui/asset/list, /api/gui/files/export/csv/, /api/gui/files/list, /api/gui/process/export/csv, /api/gui/process/export/xlsx, /api/gui/process/listAll, /api/gui/processVersion/export/csv/, /api/gui/processVersion/export/xlsx/, /api/gui/processVersion/list/, /api/gui/robot/list/, /api/gui/task/export/csv/, /api/gui/task/export/xlsx/, and /api/gui/task/list/. | |
| Weaknesses | CWE-89 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: mitre
Published: 2025-04-25T00:00:00.000Z
Updated: 2025-04-25T14:29:53.040Z
Reserved: 2025-04-24T00:00:00.000Z
Link: CVE-2025-46546
Updated: 2025-04-25T14:29:50.348Z
Status : Analyzed
Published: 2025-04-25T03:15:20.270
Modified: 2025-10-16T20:42:14.710
Link: CVE-2025-46546
No data.