CVE-2025-4377: Sparx Systems Pro Cloud Server
High severity, CVSS 8.3. EPSS: 0.8% chance of exploitation in the next 30 days.
Improper Limitation of a Pathname caused a Path Traversal vulnerability in Sparx Systems Pro Cloud Server. This vulnerability is present in logview.php and it allows reading arbitrary files on the filesystem. Logview is accessible on Pro Cloud Server Configuration interface. This issue affects Pro Cloud Server: earlier than 6.0.165.
Affected products
- Sparx Systems Pro Cloud Server: up to and including 6.0.163
Published 2025-05-09. Last modified 2026-06-17.