CVE-2025-4377
Severity CVSS v4.0:
HIGH
Type:
CWE-20
Input Validation
Publication date:
09/05/2025
Last modified:
12/05/2025
Description
Improper Limitation of a Pathname caused a Path Traversal vulnerability in Sparx Systems Pro Cloud Server.<br />
<br />
This vulnerability is present in logview.php and it allows reading arbitrary files on the filesystem. <br />
<br />
Logview is accessible on Pro Cloud Server Configuration interface. <br />
<br />
<br />
This issue affects Pro Cloud Server: earlier than 6.0.165.
Impact
Base Score 4.0
8.30
Severity 4.0
HIGH



