Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2025-35052


Newforma Info Exchange (NIX) uses a hard-coded key to encrypt certain query parameters. Some encrypted parameter values can specify paths to download files, potentially bypassing authentication and authorization, for example, the 'qs' parameter used in '/DownloadWeb/download.aspx'. This key is shared across NIX installations. NIX 2023.3 and 2024.1 limit the use of hard-coded keys.


Published

2025-10-09T21:15:36.040

Last Modified

2025-10-22T15:56:25.910

Status

Analyzed

Source

9119a7d8-5eab-497f-8521-727c672e3725

Severity

CVSSv3.1: 5.3 (MEDIUM)

Weaknesses
  • Type: Secondary
    CWE-321

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application newforma project_center ≤ 2024.3 Yes

References