First published: Fri Apr 25 2025(Updated: )
In Sherpa Orchestrator 141851, the functionality for adding or updating licenses allows for stored XSS attacks by an administrator through the name parameter. The XSS payload can execute when the license expires.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Sherpa Orchestrator |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-46545 is classified as a high-severity vulnerability due to the potential for stored XSS attacks.
To fix CVE-2025-46545, ensure that input validation and sanitization are implemented for the name parameter when adding or updating licenses.
CVE-2025-46545 affects users of Sherpa Orchestrator version 141851.
CVE-2025-46545 allows for stored cross-site scripting (XSS) attacks through the name parameter exploited by an administrator.
The XSS payload in CVE-2025-46545 can execute when the added license expires.