Plaintext Password Storage Vulnerability in Sparx Pro Cloud Server by Sparx Systems
CVE-2025-15624

9.3CRITICAL

Key Information:

Vendor
CVE Published:
17 April 2026

What is CVE-2025-15624?

A vulnerability exists in Sparx Pro Cloud Server where user passwords utilized in conjunction with OpenID as an authentication method are stored in plaintext. This flaw may expose sensitive user information and increase the risk of unauthorized access to user accounts. Users are encouraged to review their security practices and consider applying any available patches or updates.

Affected Version(s)

Sparx Pro Cloud Server 6.0.163

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Pasi Orovuo, Solita Oy
Henri Hämäläinen, Solita Oy
Samu Ahvenainen, Solita Oy
.