← volver
CVE-2025-4377highCWE-20CWE-22

Path traversal vulnerability in Sparx Pro Cloud Server WebEA webconfig in logview.php

21Vexday Risk Score

Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.

ssvc Trackcvss 8.3epss 0.7%
probabilidad de explotación
0.7%top 51% de las CVE
explotación observada
noninguna fuente lo reporta
Improper Limitation of a Pathname caused a Path Traversal vulnerability in Sparx Systems Pro Cloud Server. This vulnerability is present in logview.php and it allows reading arbitrary files on the filesystem.  Logview is accessible on Pro Cloud Server Configuration interface. This issue affects Pro Cloud Server: earlier than 6.0.165.
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:L/VA:L/SC:H/SI:N/SA:N