CVE-2025-15623
โ ๏ธ highSummary
Exposure of Private Personal Information to an Unauthorized Actor, : Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Sparx Systems Pty Ltd. Sparx Pro Cloud Server. Unauthenticated user can retrieve database password in plaintext in certain situations
CVSS Score
7.5
High
EPSS Score
0.1
Exploit Probability
Published Date
2026-04-17
First Seen: 2026-04-20
๐ Relative Risk Intelligence
This CVE is Moderate Risk - more severe than 69.0% of all 326,604 vulnerabilities in our database.
#101,315
Above average severity
Severity Percentile
๐ฏ CISA SSVC Assessment Updated: Apr 17, 2026
๐ Exploitation Status
None
No known exploits
โ๏ธ Automatable
YES
Can be exploited automatically
๐ฅ Technical Impact
Total
Complete system compromise possible
๐ Discovered By
Pasi Orovuo, Solita Oy
Henri Hรคmรคlรคinen, Solita Oy
Samu Ahvenainen, Solita Oy
SSVC data provided by
CISA
Last Modified
2026-06-02
Source
NVD ๐
CVSS Vector 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS Vector 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:P/AU:Y/R:X/V:C/RE:M/U:Red