216.73.216.6

CVE-2025-4377

· Published 09/05/2025 06:15 · Modified 09/05/2025 06:15

Labels: CVE-2025-4377 2025-05-09CVE-2025-4377CWE-20db4dfee8-a97e-4877-bfae-eba6d14a2166

Essential information

Published
09/05/2025 06:15
Modified
09/05/2025 06:15
Author
Creator
CVSS
8.3 HIGH (v3) 8.3 HIGH (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

Improper Limitation of a Pathname caused a Path Traversal vulnerability in Sparx Systems Pro Cloud Server. This vulnerability is present in logview.php and it allows reading arbitrary files on the filesystem.  Logview is accessible on Pro Cloud Server Configuration interface. This issue affects Pro Cloud Server: earlier than 6.0.165.

NVD status

Status
Received — CVE has been recently published to the CVE List and has been received by the NVD.
Source
db4dfee8-a97e-4877-bfae-eba6d14a2166
NVD
View on NVD

Affected products (CPE)

ProductCPE
sparx / pro cloud server cpe:2.3:a:sparx:pro_cloud_server:<6.0.165:*:*:*:*:*:*:*

References