Search
Search Results (5 CVEs found)
CVE | Vendors | Products | Updated | CVSS v3.1 |
---|---|---|---|---|
CVE-2025-35062 | 1 Newforma | 2 Newforma Info Exchange, Project Center Server | 2025-10-21 | 5.3 Medium |
Newforma Info Exchange (NIX) before version 2023.1 by default allows anonymous authentication which allows an unauthenticated attacker to exploit additional vulnerabilities that require authentication. | ||||
CVE-2025-35061 | 1 Newforma | 2 Newforma Info Exchange, Project Center Server | 2025-10-21 | 5.9 Medium |
Newforma Info Exchange (NIX) '/NPCSRemoteWeb/LegacyIntegrationServices.asmx' allows a remote, unauthenticated attacker to cause NIX to make an SMB connection to an attacker-controlled system. The attacker can capture the NTLMv2 hash of the user-configured NIX service account. | ||||
CVE-2025-35060 | 1 Newforma | 2 Newforma Info Exchange, Project Center Server | 2025-10-21 | 5.5 Medium |
Newforma Info Exchange (NIX) provides a 'Send a File Transfer' feature that allows a remote, authenticated attacker to upload SVG files that contain JavaScript or other content that may be executed or rendered by a web browser using a mobile user agent. | ||||
CVE-2025-35059 | 1 Newforma | 2 Newforma Info Exchange, Project Center Server | 2025-10-21 | 4.3 Medium |
Newforma Info Exchange (NIX) '/DownloadWeb/hyperlinkredirect.aspx' provides an unauthenticated URL redirect via the 'nhl' parameter. | ||||
CVE-2025-35058 | 1 Newforma | 2 Newforma Info Exchange, Project Center Server | 2025-10-21 | 5.9 Medium |
Newforma Info Exchange (NIX) '/UserWeb/Common/MarkupServices.ashx' allows a remote, unauthenticated attacker to cause NIX to make an SMB connection to an attacker-controlled system. The attacker can capture the NTLMv2 hash of the customer-configured NIX service account. |
Page 1 of 1.