Impact
Unverified users can submit crafted requests that cause the Sparx Pro Cloud Server to execute arbitrary SQL statements against its database. The flaw allows attackers to read, modify, or delete data, potentially compromising confidentiality, integrity, and availability. The weakness is a classic SQL injection (CWE-89) that also leaks sensitive information (CWE-200).
Affected Systems
Sparx Systems Pty Ltd. offers the Sparx Pro Cloud Server as the affected product. Specific version details are not disclosed in the available data, so all deployments of this server should be reviewed for risk.
Risk and Exploitability
With a CVSS score of 9.5 the vulnerability is considered Critical. The EPSS score is not available, but the lack of a KEV listing does not diminish the severity; an unauthenticated attacker can reach the vulnerable input surfaces over the network, so exploitation is likely if no mitigations exist. The attack vector is inferred to be remote, based on the description of unauthenticated access. Due to the high score, the risk to any exposed instance warrants rapid response.
OpenCVE Enrichment