CVE-2025-15623Disclosure(sparxsystems / pro_cloud_server)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Exposure of Private Personal Information to an Unauthorized Actor, : Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Sparx Systems Pty Ltd. Sparx Pro Cloud Server. Unauthenticated user can retrieve database password in plaintext in certain situations

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-359CWE-497

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • pro_cloud_server

Threat summary

  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • General: 2 classified signals
  • Peaked 1d ago at 3 mentions (2026-04-17); latest day: 1
  • 4 total mentions across 2 days

Affected systems

Products
pro_cloud_server

1 version affected across 1 product

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-04-17: 3Mentions · 2026-06-02: 1Technical Details · 2026-04-17: 204-1706-02
Signal classification2 categories
Disclosure
250.0%
General
250.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-04-173
Disclosure1General2
2026-06-021
Disclosure1
Full discourse4 posts
  • DailyCVE@dailycve
    Disclosure

    🔴 Sparx Pro Cloud Server, Information Disclosure, #CVE-2025-15623 (Critical) -DC-Jun2026-110 https://dailycve.com/sparx-pro-cloud-server-information-disclosure-cve-2025-15623-critical-dc-jun2026-110/

    Post summary

    The text announces the existence of a new critical information disclosure vulnerability (CVE‑2025‑15623) in Sparx Pro Cloud Server, without providing technical, exploitation, or patch details.

    0000030
    209 followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2025-15623: Sparx Pro Cloud Server reveals s... Database passwords in plaintext over the wire with zero auth required - Sparx just handed every attacker the keys to th... https://zerodaysignal.com/vulnerability/CVE-2025-15623 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The post discloses CVE-2025-15623, noting that Sparx Pro Cloud Server transmits database credentials in plaintext with no authentication, but does not mention PoC, exploitation status, or a patch.

    00000555
    218 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2025-15623 Unauthenticated Database Password Exposure in Sparx Systems Pro Cloud Server https://vulmon.com/vulnerabilitydetails?qid=CVE-2025-15623

    Post summary

    The entry notes the CVE ID and a brief description of an unauthenticated password exposure flaw, but lacks detailed technical data, exploit code, or patch information.

    00000185
    4.0K followersView on X
  • CVE@CVEnew
    General

    CVE-2025-15623 Exposure of Private Personal Information to an Unauthorized Actor, : Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Sparx… https://www.cve.org/CVERecord?id=CVE-2025-15623

    Post summary

    The message simply cites the CVE record with a brief description of information exposure, offering no technical depth or exploitation details.

    00000198
    57.2K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appsparxsystemspro_cloud_server6.0.163--

Explore more