SQL Injection Vulnerability in Sparx Pro Cloud Server by Sparx Systems
CVE-2025-15625
9.5CRITICAL
What is CVE-2025-15625?
An authentication bypass vulnerability exists in Sparx Pro Cloud Server, allowing unauthenticated users to execute arbitrary SQL commands against the database. This can lead to unauthorized access to sensitive data, data manipulation, or even complete compromise of the database. Users are advised to review their security measures and apply necessary updates to protect against potential exploitation.
Affected Version(s)
Sparx Pro Cloud Server 6.0.163
References
CVSS V4
Score:
9.5
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Pasi Orovuo, Solita Oy
Henri Hämäläinen, Solita Oy
Samu Ahvenainen, Solita Oy
