← Back

CVE-2025-46545

nvd nist
Published: Apr 25, 2025Modified: Oct 15, 2025

JSON object

Loading...
4.8
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Exploitability: 1.7 / Impact: 2.7
Source: NVD

Description

In Sherpa Orchestrator 141851, the functionality for adding or updating licenses allows for stored XSS attacks by an administrator through the name parameter. The XSS payload can execute when the license expires.

Affected (1)

1 product
Sherpa Orchestrator
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 141851

References (4)

Source: cve@mitre.org
Not Applicable
Source: cve@mitre.org
Product
Source: cve@mitre.org
Not Applicable

Timeline

No history available yet.