# CVE-2025-15623

## Summary

- **CVE ID:** CVE-2025-15623
- **Severity:** CRITICAL
- **CVSS Score:** 9.3 (CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:L/SI:L/SA:N/S:P/AU:Y/V:C/RE:M/U:Red)
- **CWE:** CWE-359, CWE-497
- **Published:** Apr 17, 2026
- **Last Modified:** Apr 17, 2026

## Description

Exposure of Private Personal Information to an Unauthorized Actor, : Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Sparx Systems Pty Ltd. Sparx Pro Cloud Server.

Unauthenticated user can retrieve database password in plaintext in certain situations

## Affected Products

- Sparx Systems Pty Ltd. — Sparx Pro Cloud Server (6.0.163)

## References

- [CNA](https://sparxsystems.com/products/procloudserver/6.1/history.html)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.26%
- **EPSS Percentile:** 17.9

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-11._