Sparx Pro Cloud Server requires authentication based on requested URL. An attacker can omit the "model" query parameter and send the model name only in the binary blob in POST request allowing SQL query execution without authentication. The vendor was notified early about this vulnerability, but didn't respond with the details of vulnerability or vulnerable version range. Only version 6.1 (build 167) and below were tested and confirmed as vulnerable, other versions were not tested and might also be vulnerable.
The application verifies user identity based on the 'model' parameter contained in the request URL. An attacker can omit this parameter in the URL and instead place the model name solely in the binary content (blob) of the POST request body. The authentication mechanism does not properly analyze this alternative path, as a result the SQL query reaches the database without prior verification of the requester's identity. This is a vulnerability classified as CWE-639 (Authorization Bypass Through User-Controlled Key) with a SQL injection component.
An unauthenticated remote attacker can execute arbitrary SQL queries in the server's database, which may lead to unauthorized reading and modification of stored data, including potentially sensitive architectural modeling data.
Patches available from the manufacturer should be applied according to references. Since the manufacturer did not respond to the vulnerability report, it is recommended to restrict network access to Sparx Pro Cloud Server instances (e.g., through firewall or VPN) and monitor HTTP traffic for suspicious POST requests until an official patch is released.
Sparx Pro Cloud Server version 6.1 (build 167) and lower — confirmed vulnerable. Other versions were not tested and may also be vulnerable. The manufacturer did not provide information about the scope of vulnerable versions.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XSparxsystems Pro Cloud Server
APPSparxsystems≤ 6.1.167
Related vulnerabilities
Sparx Pro Cloud Server: ujawnienie hasła do bazy danych w plaintext
Plaintext Storage haseł w Sparx Pro Cloud Server z OpenID
SQL Injection w Sparx Pro Cloud Server — nieautoryzowany dostęp do bazy danych
Sparx Pro Cloud Server is vulnerable to Broken Access Control within communication with the database. Due to l...
Sparx Pro Cloud Server is vulnerable to a Race Condition in the /data_api/dl_internal_artifact.php endpoint. T...