{
    "dataType": "CVE_RECORD",
    "dataVersion": "5.1",
    "cveMetadata": {
        "cveId": "CVE-2025-4377",
        "assignerOrgId": "db4dfee8-a97e-4877-bfae-eba6d14a2166",
        "state": "PUBLISHED",
        "assignerShortName": "NCSC-FI",
        "dateReserved": "2025-05-06T05:21:12.322Z",
        "datePublished": "2025-05-09T05:12:59.487Z",
        "dateUpdated": "2025-05-09T13:22:16.817Z"
    },
    "containers": {
        "cna": {
            "affected": [
                {
                    "collectionURL": "https://sparxsystems.com/products/procloudserver/",
                    "defaultStatus": "unaffected",
                    "platforms": [
                        "Windows"
                    ],
                    "product": "Pro Cloud Server",
                    "programFiles": [
                        "logview.php"
                    ],
                    "vendor": "Sparx Systems",
                    "versions": [
                        {
                            "lessThanOrEqual": "6.0.163",
                            "status": "affected",
                            "version": "0",
                            "versionType": "PCS"
                        },
                        {
                            "status": "unaffected",
                            "version": "6.0.165",
                            "versionType": "PCS"
                        }
                    ]
                }
            ],
            "credits": [
                {
                    "lang": "en",
                    "type": "finder",
                    "value": "Santeri Siirilä"
                },
                {
                    "lang": "en",
                    "type": "finder",
                    "value": "Mikko Korpi"
                }
            ],
            "datePublic": "2025-05-05T06:00:00.000Z",
            "descriptions": [
                {
                    "lang": "en",
                    "supportingMedia": [
                        {
                            "base64": false,
                            "type": "text/html",
                            "value": "<div>Improper Limitation of a Pathname caused a Path Traversal vulnerability in Sparx Systems Pro Cloud Server.</div><div>This vulnerability is present in <tt>logview.php</tt> and it allows reading arbitrary files on the filesystem.&nbsp;</div><div>Logview is accessible on Pro Cloud Server Configuration interface. <br></div><p>This issue affects Pro Cloud Server: earlier than 6.0.165.</p>"
                        }
                    ],
                    "value": "Improper Limitation of a Pathname caused a Path Traversal vulnerability in Sparx Systems Pro Cloud Server.\n\nThis vulnerability is present in logview.php and it allows reading arbitrary files on the filesystem. \n\nLogview is accessible on Pro Cloud Server Configuration interface. \n\n\nThis issue affects Pro Cloud Server: earlier than 6.0.165."
                }
            ],
            "impacts": [
                {
                    "capecId": "CAPEC-126",
                    "descriptions": [
                        {
                            "lang": "en",
                            "value": "CAPEC-126: Path Traversal"
                        }
                    ]
                },
                {
                    "capecId": "CAPEC-139",
                    "descriptions": [
                        {
                            "lang": "en",
                            "value": "CAPEC-139: Relative Path Traversal"
                        }
                    ]
                }
            ],
            "metrics": [
                {
                    "cvssV4_0": {
                        "Automatable": "NOT_DEFINED",
                        "Recovery": "NOT_DEFINED",
                        "Safety": "NOT_DEFINED",
                        "attackComplexity": "LOW",
                        "attackRequirements": "NONE",
                        "attackVector": "NETWORK",
                        "baseScore": 8.3,
                        "baseSeverity": "HIGH",
                        "privilegesRequired": "HIGH",
                        "providerUrgency": "NOT_DEFINED",
                        "subAvailabilityImpact": "NONE",
                        "subConfidentialityImpact": "HIGH",
                        "subIntegrityImpact": "NONE",
                        "userInteraction": "NONE",
                        "valueDensity": "NOT_DEFINED",
                        "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:L/VA:L/SC:H/SI:N/SA:N",
                        "version": "4.0",
                        "vulnAvailabilityImpact": "LOW",
                        "vulnConfidentialityImpact": "HIGH",
                        "vulnIntegrityImpact": "LOW",
                        "vulnerabilityResponseEffort": "NOT_DEFINED"
                    },
                    "format": "CVSS",
                    "scenarios": [
                        {
                            "lang": "en",
                            "value": "GENERAL"
                        }
                    ]
                }
            ],
            "problemTypes": [
                {
                    "descriptions": [
                        {
                            "cweId": "CWE-22",
                            "description": "CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
                            "lang": "en",
                            "type": "CWE"
                        }
                    ]
                },
                {
                    "descriptions": [
                        {
                            "cweId": "CWE-20",
                            "description": "CWE-20 Improper Input Validation",
                            "lang": "en",
                            "type": "CWE"
                        }
                    ]
                }
            ],
            "providerMetadata": {
                "orgId": "db4dfee8-a97e-4877-bfae-eba6d14a2166",
                "shortName": "NCSC-FI",
                "dateUpdated": "2025-05-09T05:12:59.487Z"
            },
            "references": [
                {
                    "url": "https://sparxsystems.com/products/procloudserver/6.1/"
                }
            ],
            "source": {
                "discovery": "UNKNOWN"
            },
            "title": "Path traversal vulnerability in Sparx Pro Cloud Server WebEA webconfig in logview.php",
            "x_generator": {
                "engine": "Vulnogram 0.2.0"
            }
        },
        "adp": [
            {
                "metrics": [
                    {
                        "other": {
                            "type": "ssvc",
                            "content": {
                                "timestamp": "2025-05-09T13:22:04.482705Z",
                                "id": "CVE-2025-4377",
                                "options": [
                                    {
                                        "Exploitation": "none"
                                    },
                                    {
                                        "Automatable": "yes"
                                    },
                                    {
                                        "Technical Impact": "partial"
                                    }
                                ],
                                "role": "CISA Coordinator",
                                "version": "2.0.3"
                            }
                        }
                    }
                ],
                "title": "CISA ADP Vulnrichment",
                "providerMetadata": {
                    "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
                    "shortName": "CISA-ADP",
                    "dateUpdated": "2025-05-09T13:22:16.817Z"
                }
            }
        ]
    }
}