CVE-2025-4375

Cross-Site Request Forgery (CSRF) vulnerability in Sparx Systems Pro Cloud Server allows Cross-Site Request Forgery to perform Session Hijacking. Cross-Site Request Forgery is present at the whole application but it can be used to change the Pro Cloud Server Configuration password. This issue affects Pro Cloud Server: earlier than 6.0.165.
CVSS

No CVSS.

Configurations

No configuration.

History

12 May 2025, 17:32

Type Values Removed Values Added
Summary
  • (es) La vulnerabilidad de Cross-Site Request Forgery (CSRF) en Sparx Systems Pro Cloud Server permite que esta vulnerabilidad realice secuestros de sesión. Esta vulnerabilidad está presente en toda la aplicación, pero puede utilizarse para cambiar la contraseña de configuración de Pro Cloud Server. Este problema afecta a Pro Cloud Server: versiones anteriores a la 6.0.165.

09 May 2025, 06:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-05-09 06:15

Updated : 2025-05-12 17:32


NVD link : CVE-2025-4375

Mitre link : CVE-2025-4375

CVE.ORG link : CVE-2025-4375


JSON object : View

Products Affected

No product.

CWE
CWE-352

Cross-Site Request Forgery (CSRF)