Sherpa Orchestrator Cross-Site Request Forgery Vulnerability Allowing XSS, SQL Injection, and Access Control Issues

Vulnerability

A cross-site request forgery (CSRF) vulnerability has been identified in Sherpa Orchestrator version 141851. The web application does not have adequate protection against CSRF attacks, which can lead to various security issues. An attacker could exploit this vulnerability to perform cross-site scripting (XSS) attacks, manipulate user roles or access controls, or take advantage of existing SQL injection vulnerabilities within the application.

Impact

Exploitation of this vulnerability could result in successful CSRF attacks, allowing for XSS exploitation, unauthorized access control changes, or the exploitation of SQL injection vulnerabilities.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
3.5
exploitability
6.4
remediation
0.0
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.