In Sherpa Orchestrator 141851, multiple time-based blind SQL injections can be performed by an authenticated user. This affects api/gui/asset/list, /api/gui/files/export/csv/, /api/gui/files/list, /api/gui/process/export/csv, /api/gui/process/export/xlsx, /api/gui/process/listAll, /api/gui/processVersion/export/csv/, /api/gui/processVersion/export/xlsx/, /api/gui/processVersion/list/, /api/gui/robot/list/, /api/gui/task/export/csv/, /api/gui/task/export/xlsx/, and /api/gui/task/list/.
                
            Metrics
Affected Vendors & Products
References
        History
                    Thu, 16 Oct 2025 20:45:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| First Time appeared | 
        
        Sherparpa
         Sherparpa sherpa Orchestrator  | 
|
| CPEs | cpe:2.3:a:sherparpa:sherpa_orchestrator:141851:*:*:*:*:*:*:* | |
| Vendors & Products | 
        
        Sherparpa
         Sherparpa sherpa Orchestrator  | 
Fri, 25 Apr 2025 15:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Metrics | 
        
        ssvc
         
  | 
Fri, 25 Apr 2025 03:00:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Description | In Sherpa Orchestrator 141851, multiple time-based blind SQL injections can be performed by an authenticated user. This affects api/gui/asset/list, /api/gui/files/export/csv/, /api/gui/files/list, /api/gui/process/export/csv, /api/gui/process/export/xlsx, /api/gui/process/listAll, /api/gui/processVersion/export/csv/, /api/gui/processVersion/export/xlsx/, /api/gui/processVersion/list/, /api/gui/robot/list/, /api/gui/task/export/csv/, /api/gui/task/export/xlsx/, and /api/gui/task/list/. | |
| Weaknesses | CWE-89 | |
| References | 
         | |
| Metrics | 
        
        cvssV3_1
         
  | 
Status: PUBLISHED
Assigner: mitre
Published: 2025-04-25T00:00:00.000Z
Updated: 2025-04-25T14:29:53.040Z
Reserved: 2025-04-24T00:00:00.000Z
Link: CVE-2025-46546
Updated: 2025-04-25T14:29:50.348Z
Status : Analyzed
Published: 2025-04-25T03:15:20.270
Modified: 2025-10-16T20:42:14.710
Link: CVE-2025-46546
No data.
ReportizFlow