Search Results (5 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2025-35062 1 Newforma 2 Newforma Info Exchange, Project Center Server 2025-10-21 5.3 Medium
Newforma Info Exchange (NIX) before version 2023.1 by default allows anonymous authentication which allows an unauthenticated attacker to exploit additional vulnerabilities that require authentication.
CVE-2025-35061 1 Newforma 2 Newforma Info Exchange, Project Center Server 2025-10-21 5.9 Medium
Newforma Info Exchange (NIX) '/NPCSRemoteWeb/LegacyIntegrationServices.asmx' allows a remote, unauthenticated attacker to cause NIX to make an SMB connection to an attacker-controlled system. The attacker can capture the NTLMv2 hash of the user-configured NIX service account.
CVE-2025-35060 1 Newforma 2 Newforma Info Exchange, Project Center Server 2025-10-21 5.5 Medium
Newforma Info Exchange (NIX) provides a 'Send a File Transfer' feature that allows a remote, authenticated attacker to upload SVG files that contain JavaScript or other content that may be executed or rendered by a web browser using a mobile user agent.
CVE-2025-35059 1 Newforma 2 Newforma Info Exchange, Project Center Server 2025-10-21 4.3 Medium
Newforma Info Exchange (NIX) '/DownloadWeb/hyperlinkredirect.aspx' provides an unauthenticated URL redirect via the 'nhl' parameter.
CVE-2025-35058 1 Newforma 2 Newforma Info Exchange, Project Center Server 2025-10-21 5.9 Medium
Newforma Info Exchange (NIX) '/UserWeb/Common/MarkupServices.ashx' allows a remote, unauthenticated attacker to cause NIX to make an SMB connection to an attacker-controlled system. The attacker can capture the NTLMv2 hash of the customer-configured NIX service account.