CRITICAL🇵🇱 Wersja polska

CVE-2025-15625

CVSS 9.5v4.0pub. 2026-04-17upd. 2026-06-02

Unauthenticated user is able to execute arbitrary SQL commands in Sparx Pro Cloud Server database in certain cases.

🤖 AI Analysis
How it works

The SQL injection vulnerability (CWE-89) allows an attacker to inject malicious SQL instructions into queries directed at the application database. Lack of proper validation or parameterization of input data enables execution of arbitrary SQL commands without the need for authentication. Additionally, the CWE-200 vulnerability indicates the possibility of unauthorized disclosure of sensitive information stored in the database.

Impact

An attacker can read, modify, or delete data from the application database, and under favorable conditions gain broader access to the system. It is also possible to disclose sensitive information stored in the Sparx Pro Cloud Server database.

Mitigation & patch

Apply patches available from the manufacturer according to the references — a detailed list of patched versions is available in the Sparx Pro Cloud Server change history at: https://sparxsystems.com/products/procloudserver/6.1/history.html

Who is affected

Sparx Pro Cloud Server — versions indicated in the manufacturer's references (change history available at sparxsystems.com/products/procloudserver/6.1/history.html)

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:P/AU:Y/R:I/V:C/RE:M/U:Red
  • Sparxsystems Pro Cloud Server

    APP
    Sparxsystems
    6.0.163
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
SQLi
CWE
References

Related vulnerabilities

CVE-2026-42097CRITICAL9.3PL ✓same product

Sparx Pro Cloud Server — SQL injection bez uwierzytelnienia przez pominięcie parametru

CVE-2025-15623CRITICAL9.3PL ✓same product

Sparx Pro Cloud Server: ujawnienie hasła do bazy danych w plaintext

CVE-2025-15624CRITICAL9.3PL ✓same product

Plaintext Storage haseł w Sparx Pro Cloud Server z OpenID

CVE-2026-42096HIGH8.7same product

Sparx Pro Cloud Server is vulnerable to Broken Access Control within communication with the database. Due to l...

CVE-2026-42099HIGH7.7same product

Sparx Pro Cloud Server is vulnerable to a Race Condition in the /data_api/dl_internal_artifact.php endpoint. T...