QSearchQSearch

CVE-2025-15623

7.5 HIGH

Exposure of Private Personal Information to an Unauthorized Actor, : Exposure of Sensitive System Information to an Unauthorized Control ...

Published: 2026-04-17 · Last updated: 2026-06-02

Severity and scoring

CVSS
7.5 HIGH
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CWE
CWE-359, CWE-497

Affected products

VendorProduct
sparxsystemspro_cloud_server

Description

Exposure of Private Personal Information to an Unauthorized Actor, : Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Sparx Systems Pty Ltd. Sparx Pro Cloud Server. Unauthenticated user can retrieve database password in plaintext in certain situations

Source: NVD

References

Related CVEs

Same vendor

  • CVE-2026-42100 Improper Handling of Syntactically Invalid Structure in Sparx Pro Cloud Server allows Denial of Service (DoS) attack to be executed by se... (7.5 HIGH)
  • CVE-2026-42099 Sparx Pro Cloud Server is vulnerable to a Race Condition in the /data_api/dl_internal_artifact.php endpoint (7.5 HIGH)
  • CVE-2026-42097 Sparx Pro Cloud Server requires authentication based on requested URL (8.8 HIGH)
  • CVE-2026-42096 Sparx Pro Cloud Server is vulnerable to Broken Access Control within communication with the database (8.8 HIGH)
  • CVE-2025-15625 Unauthenticated user is able to execute arbitrary SQL commands in Sparx Pro Cloud Server database in certain cases (9.8 CRITICAL)

Same CWE

  • CVE-2026-9307 A sensitive information disclosure security issue exists within the affected CompactLogix controllers
  • CVE-2026-52694 Unauthenticated Sensitive Data Exposure in Signature Add-On for WooCommerce <= 2.0 versions (7.5 HIGH)
  • CVE-2026-49068 Subscriber Sensitive Data Exposure in Coupon Affiliates <= 7.8.1 versions (7.5 HIGH)
  • CVE-2026-49066 Unauthenticated Sensitive Data Exposure in Conekta Payment Gateway <= 6.0.0 versions (7.5 HIGH)
  • CVE-2026-49056 Unauthenticated Sensitive Data Exposure in WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels <= 4.9.4 versions (7.5 HIGH)