---
id: CVE-2025-15623
title: >-
  Exposure of Private Personal Information to an Unauthorized Actor, : Exposure
  of Sensitive System Information to an Unauthorized Control Sphere
  vulnerability in Sparx Systems Pty Ltd
summary: >-
  Exposure of Private Personal Information to an Unauthorized Actor, : Exposure
  of Sensitive System Information to an Unauthorized Control Sphere
  vulnerability in Sparx Systems Pty Ltd. Sparx Pro Cloud Server.


  Unauthenticated user can ret…
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'
cwe:
  - CWE-359
  - CWE-497
vendor: sparxsystems
product: pro_cloud_server
affected:
  - pro_cloud_server = 6.0.163
published: '2026-04-17'
updated: '2026-09-30'
sourceUpdated: '2026-09-30T22:10:00.273'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-15623'
references:
  - url: 'https://sparxsystems.com/products/procloudserver/6.1/history.html'
    label: db4dfee8-a97e-4877-bfae-eba6d14a2166
tags:
  - nvd
epss: 0.00261
epssPercentile: 0.16171
ingestedAt: '2026-09-30T22:27:27.760Z'
---

## Overview

Exposure of Private Personal Information to an Unauthorized Actor, : Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Sparx Systems Pty Ltd. Sparx Pro Cloud Server.

Unauthenticated user can retrieve database password in plaintext in certain situations

## Affected

- `pro_cloud_server = 6.0.163`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
