This issue affects Pro Cloud Server: earlier than 6.0.165.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-14086 | Cross-Site Request Forgery (CSRF) vulnerability in Sparx Systems Pro Cloud Server allows Cross-Site Request Forgery to perform Session Hijacking. Cross-Site Request Forgery is present at the whole application but it can be used to change the Pro Cloud Server Configuration password. This issue affects Pro Cloud Server: earlier than 6.0.165. |
| Link | Providers |
|---|---|
| https://sparxsystems.com/products/procloudserver/6.1/ |
|
Wed, 16 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Fri, 09 May 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 09 May 2025 05:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Cross-Site Request Forgery (CSRF) vulnerability in Sparx Systems Pro Cloud Server allows Cross-Site Request Forgery to perform Session Hijacking. Cross-Site Request Forgery is present at the whole application but it can be used to change the Pro Cloud Server Configuration password. This issue affects Pro Cloud Server: earlier than 6.0.165. | |
| Title | Cross-Site Request Forgery vulnerability in Pro Cloud Server's WebEA | |
| Weaknesses | CWE-352 | |
| References |
| |
| Metrics |
cvssV4_0
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: NCSC-FI
Published:
Updated: 2025-05-09T13:24:21.744Z
Reserved: 2025-05-06T05:21:08.411Z
Link: CVE-2025-4375
Updated: 2025-05-09T13:24:18.623Z
Status : Deferred
Published: 2025-05-09T06:15:37.687
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-4375
No data.
OpenCVE Enrichment
No data.
EUVD