9.5
/ 10
CRITICAL
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/S:P/AU:Y/R:I/V:C/RE:M/U:Red
Description
Unauthenticated user is able to execute arbitrary SQL commands in Sparx Pro Cloud Server database in certain cases.
AI Analysis
Unauthenticated execution of arbitrary SQL queries in Sparx Pro Cloud Server
Basic Information
ID
CVE-2025-15625
Source
NCSC-FI
Published
Apr 17, 2026 at 08:38
Affected Product
Vendor
Sparx Systems Pty Ltd.
Product
Sparx Pro Cloud Server
Version
6.0.163
Affected Versions
Sparx Systems Pty Ltd. Sparx Pro Cloud Server 6.0.163
CWE Classification
AI Assessment
AI Score
9.5 / 10
AI Severity
Critical
Vendor
Sparx Systems Pty Ltd.
Product
Sparx Pro Cloud Server
Version
6.0.163