ZeroHour

CVE-2025-15625

CVSS 4.0
9.5 critical
EPSS
<1%p35
Published
()
Modified
Description

Unauthenticated user is able to execute arbitrary SQL commands in Sparx Pro Cloud Server database in certain cases.

Vendors
sparxsystems
Products
pro cloud server
Weakness
CWE-89, CWE-200
Vector
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:P/AU:Y/R:I/V:C/RE:M/U:Red

In the news

No ingested article mentions this CVE yet.