Sparxsystems

Pro Cloud Server

7 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.68%
  • Veröffentlicht 19.05.2026 12:59:50
  • Zuletzt bearbeitet 02.06.2026 14:19:20

Improper Handling of Syntactically Invalid Structure in Sparx Pro Cloud Server allows Denial of Service (DoS) attack to be executed by sending an specially crafted SQL query. This causes the Pro Cloud Server service to terminate unexpectedly.  The v...

Exploit
  • EPSS 0.72%
  • Veröffentlicht 19.05.2026 12:59:38
  • Zuletzt bearbeitet 02.06.2026 14:23:06

Sparx Pro Cloud Server is vulnerable to a Race Condition in the /data_api/dl_internal_artifact.php endpoint. The application downloads the properties of the object pointed by guid parameter and saves loaded content in current location (__DIR__) under...

Exploit
  • EPSS 0.94%
  • Veröffentlicht 19.05.2026 12:59:19
  • Zuletzt bearbeitet 02.06.2026 14:22:20

Sparx Pro Cloud Server requires authentication based on requested URL. An attacker can omit the "model" query parameter and send the model name only in the binary blob in POST request allowing SQL query execution without authentication. The vendor w...

Exploit
  • EPSS 0.6%
  • Veröffentlicht 19.05.2026 12:59:10
  • Zuletzt bearbeitet 02.06.2026 14:20:58

Sparx Pro Cloud Server is vulnerable to Broken Access Control within communication with the database. Due to lack of permission checks, any low privileged user can run arbitrary SQL queries within database user context. The vendor was notified early...

  • EPSS 0.42%
  • Veröffentlicht 17.04.2026 08:38:59
  • Zuletzt bearbeitet 02.06.2026 14:26:57

Unauthenticated user is able to execute arbitrary SQL commands in Sparx Pro Cloud Server database in certain cases.

  • EPSS 0.38%
  • Veröffentlicht 17.04.2026 08:38:36
  • Zuletzt bearbeitet 02.06.2026 14:26:36

Plaintext Storage of a Password vulnerability in Sparx Systems Pty Ltd. Sparx Pro Cloud Server.  In a setup where OpenID is used as the primary method of authentication to authenticate to Sparx EA, Pro Cloud Server creates local passwords to the user...

  • EPSS 0.26%
  • Veröffentlicht 17.04.2026 08:37:27
  • Zuletzt bearbeitet 02.06.2026 14:26:39

Exposure of Private Personal Information to an Unauthorized Actor, : Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Sparx Systems Pty Ltd. Sparx Pro Cloud Server. Unauthenticated user can retrieve databas...