PT-2025-41469 · Newforma · Newforma Info Exchange
Adam Merrill
+6
·
Published
2025-10-09
·
Updated
2025-10-22
·
CVE-2025-35053
CVSS v3.1
6.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:L |
Name of the Vulnerable Software and Affected Versions
Newforma Info Exchange (NIX) versions prior to 2023.1
Description
Newforma Info Exchange (NIX) allows authenticated users to read and delete arbitrary files with 'NT AUTHORITYNetworkService' privileges through requests to the
/UserWeb/Common/MarkupServices.ashx endpoint specifying the DownloadExportedPDF command. Prior to version 2023.1, anonymous access is enabled by default, allowing unauthenticated attackers to exploit this functionality by effectively authenticating as 'anonymous'. The vulnerable endpoint is /UserWeb/Common/MarkupServices.ashx and the vulnerable command is DownloadExportedPDF.Recommendations
Update to version 2023.1 or later.
Disable anonymous access to the application.
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Newforma Info Exchange