Home
MEDIUM: 5.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:NDefault status
unknown
141851 (custom)
affected
Description
In Sherpa Orchestrator 141851, the web application lacks protection against CSRF attacks, with resultant effects of an attacker conducting XSS attacks, adding a new user or role, or exploiting a SQL injection issue.
Problem types
CWE-352 Cross-Site Request Forgery (CSRF)
Product status
141851 (custom)
References
gist.github.com/ArtemBrylev/9af206c46d7505db03ad6fcd9fc46f7f