CVE-2025-15625

Unauthenticated user is able to execute arbitrary SQL commands in Sparx Pro Cloud Server database in certain cases.
Configurations

Configuration 1 (hide)

cpe:2.3:a:sparxsystems:pro_cloud_server:6.0.163:*:*:*:*:*:*:*

History

02 Jun 2026, 14:26

Type Values Removed Values Added
First Time Sparxsystems pro Cloud Server
Sparxsystems
References () https://sparxsystems.com/products/procloudserver/6.1/history.html - () https://sparxsystems.com/products/procloudserver/6.1/history.html - Release Notes
CPE cpe:2.3:a:sparxsystems:pro_cloud_server:6.0.163:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8

17 Apr 2026, 09:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-17 09:16

Updated : 2026-06-02 14:26


NVD link : CVE-2025-15625

Mitre link : CVE-2025-15625

CVE.ORG link : CVE-2025-15625


JSON object : View

Products Affected

sparxsystems

  • pro_cloud_server
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

CWE-200

Exposure of Sensitive Information to an Unauthorized Actor