CVE-2025-15624
Severity CVSS v4.0:
CRITICAL
Type:
CWE-256
Plaintext Storage of a Password
Publication date:
17/04/2026
Last modified:
17/04/2026
Description
Plaintext Storage of a Password vulnerability in Sparx Systems Pty Ltd. Sparx Pro Cloud Server. <br />
In a setup where OpenID is used as the primary method of authentication to authenticate to Sparx EA, Pro Cloud Server creates local passwords to the users and stores them in plaintext.



