SQL Injection Vulnerability in Sparx Pro Cloud Server by Sparx Systems
CVE-2025-15625

9.5CRITICAL

Key Information:

Vendor
CVE Published:
17 April 2026

What is CVE-2025-15625?

An authentication bypass vulnerability exists in Sparx Pro Cloud Server, allowing unauthenticated users to execute arbitrary SQL commands against the database. This can lead to unauthorized access to sensitive data, data manipulation, or even complete compromise of the database. Users are advised to review their security measures and apply necessary updates to protect against potential exploitation.

Affected Version(s)

Sparx Pro Cloud Server 6.0.163

References

CVSS V4

Score:
9.5
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Pasi Orovuo, Solita Oy
Henri Hämäläinen, Solita Oy
Samu Ahvenainen, Solita Oy
.