Cross-Site Request Forgery (CSRF) vulnerability in Sparx Systems Pro Cloud Server allows Cross-Site Request Forgery to perform Session Hijacking. Cross-Site Request Forgery is present at the whole application but it can be used to change the Pro Cloud Server Configuration password.
This issue affects Pro Cloud Server: earlier than 6.0.165.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://sparxsystems.com/products/procloudserver/6.1/ |
|
History
Wed, 16 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Fri, 09 May 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 09 May 2025 05:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Cross-Site Request Forgery (CSRF) vulnerability in Sparx Systems Pro Cloud Server allows Cross-Site Request Forgery to perform Session Hijacking. Cross-Site Request Forgery is present at the whole application but it can be used to change the Pro Cloud Server Configuration password. This issue affects Pro Cloud Server: earlier than 6.0.165. | |
| Title | Cross-Site Request Forgery vulnerability in Pro Cloud Server's WebEA | |
| Weaknesses | CWE-352 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: NCSC-FI
Published: 2025-05-09T05:12:48.610Z
Updated: 2025-05-09T13:24:21.744Z
Reserved: 2025-05-06T05:21:08.411Z
Link: CVE-2025-4375
Updated: 2025-05-09T13:24:18.623Z
Status : Awaiting Analysis
Published: 2025-05-09T06:15:37.687
Modified: 2025-05-12T17:32:52.810
Link: CVE-2025-4375
No data.
ReportizFlow