Improper Limitation of a Pathname caused a Path Traversal vulnerability in Sparx Systems Pro Cloud Server.
This vulnerability is present in logview.php and it allows reading arbitrary files on the filesystem.
Logview is accessible on Pro Cloud Server Configuration interface.
This issue affects Pro Cloud Server: earlier than 6.0.165.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://sparxsystems.com/products/procloudserver/6.1/ |
![]() ![]() |
History
Fri, 09 May 2025 14:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Fri, 09 May 2025 05:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Improper Limitation of a Pathname caused a Path Traversal vulnerability in Sparx Systems Pro Cloud Server. This vulnerability is present in logview.php and it allows reading arbitrary files on the filesystem. Logview is accessible on Pro Cloud Server Configuration interface. This issue affects Pro Cloud Server: earlier than 6.0.165. | |
Title | Path traversal vulnerability in Sparx Pro Cloud Server WebEA webconfig in logview.php | |
Weaknesses | CWE-20 CWE-22 |
|
References |
| |
Metrics |
cvssV4_0
|

Status: PUBLISHED
Assigner: NCSC-FI
Published: 2025-05-09T05:12:59.487Z
Updated: 2025-05-09T13:22:16.817Z
Reserved: 2025-05-06T05:21:12.322Z
Link: CVE-2025-4377

Updated: 2025-05-09T13:22:07.967Z

Status : Received
Published: 2025-05-09T06:15:38.027
Modified: 2025-05-09T06:15:38.027
Link: CVE-2025-4377

No data.