PT-2025-41472 · Newforma · Newforma Info Exchange

Adam Merrill

+6

·

Published

2025-10-09

·

Updated

2025-10-10

·

CVE-2025-35056

CVSS v3.1

5.0

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Newforma Info Exchange (NIX) (affected versions not specified)
Description The software contains a flaw in the '/UserWeb/Common/MarkupServices.ashx' endpoint, specifically within the StreamStampImage function. This function processes encrypted file paths and returns an image of the specified file. An attacker can potentially read files by providing an encrypted path. The StreamStampImage function is vulnerable to unauthorized file access.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2025-35056

Affected Products

Newforma Info Exchange