VYPR
Medium severity6.4NVD Advisory· Published Oct 9, 2025· Updated Jun 17, 2026

CVE-2025-35053

CVE-2025-35053

Description

Newforma Info Exchange (NIX) accepts requests to '/UserWeb/Common/MarkupServices.ashx' specifying the 'DownloadExportedPDF' command that allow an authenticated user to read and delete arbitrary files with 'NT AUTHORITY\NetworkService' privileges.

In Newforma before 2023.1, anonymous access is enabled by default (CVE-2025-35062), allowing an otherwise unauthenticated attacker to effectively authenticate as 'anonymous' and exploit this file upload vulnerability.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • Range: <2023.1
  • cpe:2.3:a:newforma:project_center:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:newforma:project_center:*:*:*:*:*:*:*:*range: <=2024.3
    • (no CPE)range: *

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.