Improper Limitation of a Pathname caused a Path Traversal vulnerability in Sparx Systems Pro Cloud Server. This vulnerability is present in logview.php and it allows reading arbitrary files on the filesystem.  Logview is accessible on Pro Cloud Server Configuration interface. This issue affects Pro Cloud Server: earlier than 6.0.165.
History

Fri, 09 May 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 09 May 2025 05:30:00 +0000

Type Values Removed Values Added
Description Improper Limitation of a Pathname caused a Path Traversal vulnerability in Sparx Systems Pro Cloud Server. This vulnerability is present in logview.php and it allows reading arbitrary files on the filesystem.  Logview is accessible on Pro Cloud Server Configuration interface. This issue affects Pro Cloud Server: earlier than 6.0.165.
Title Path traversal vulnerability in Sparx Pro Cloud Server WebEA webconfig in logview.php
Weaknesses CWE-20
CWE-22
References
Metrics cvssV4_0

{'score': 8.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:L/VA:L/SC:H/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: NCSC-FI

Published: 2025-05-09T05:12:59.487Z

Updated: 2025-05-09T13:22:16.817Z

Reserved: 2025-05-06T05:21:12.322Z

Link: CVE-2025-4377

cve-icon Vulnrichment

Updated: 2025-05-09T13:22:07.967Z

cve-icon NVD

Status : Received

Published: 2025-05-09T06:15:38.027

Modified: 2025-05-09T06:15:38.027

Link: CVE-2025-4377

cve-icon Redhat

No data.