Home
CRITICAL: 9.5 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/S:P/AU:Y/R:I/V:C/RE:M/U:RedDefault status
unknown
6.0.163
affected
Description
Unauthenticated user is able to execute arbitrary SQL commands in Sparx Pro Cloud Server database in certain cases.
Problem types
CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor
Product status
6.0.163
Credits
Pasi Orovuo, Solita Oy
Henri Hämäläinen, Solita Oy
Samu Ahvenainen, Solita Oy
References
sparxsystems.com/products/procloudserver/6.1/history.html