Path traversal vulnerability in Sparx Pro Cloud Server WebEA webconfig in logview.php
Vulnerability Description
Improper Limitation of a Pathname caused a Path Traversal vulnerability in Sparx Systems Pro Cloud Server. This vulnerability is present in logview.php and it allows reading arbitrary files on the filesystem. Logview is accessible on Pro Cloud Server Configuration interface. This issue affects Pro Cloud Server: earlier than 6.0.165.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-4377
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Santeri Siirilä
- Mikko Korpi
Affected Vendor
Sparx Systems
View all reports →