CVE-2025-46546 Information
Apr 26, 2025
cve
Description
In Sherpa Orchestrator 141851 multiple time-based blind SQL injections can be performed by an authenticated user. This affects api/gui/asset/list /api/gui/files/export/csv/ /api/gui/files/list /api/gui/process/export/csv /api/gui/process/export/xlsx /api/gui/process/listAll /api/gui/processVersion/export/csv/ /api/gui/processVersion/export/xlsx/ /api/gui/processVersion/list/ /api/gui/robot/list/ /api/gui/task/export/csv/ /api/gui/task/export/xlsx/ and /api/gui/task/list/.
Reference
https://deiteriy.com https://gist.github.com/ArtemBrylev/59b4c0825a988f39a58b79e4e8d2f378 https://sherparpa.com https://twitter.com/ArtyomBrylev
Share on: