Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-7cq8-vqmc-75p3

Опубликовано: 09 окт. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 5.3
CVSS3: 5

Описание

Newforma Info Exchange (NIX) '/UserWeb/Common/MarkupServices.ashx' 'StreamStampImage' accepts an encrypted file path and returns an image of the specified file. An authenticated attacker can read arbitrary files subject to the privileges of NIX, typically 'NT AUTHORITY\NetworkService', and the ability of StreamStampImage to process the file. The encrypted file path can be generated using the shared, hard-coded secret key described in CVE-2025-35052. This vulnerability cannot be exploited as an 'anonymous' user as described in CVE-2025-35062.

Newforma Info Exchange (NIX) '/UserWeb/Common/MarkupServices.ashx' 'StreamStampImage' accepts an encrypted file path and returns an image of the specified file. An authenticated attacker can read arbitrary files subject to the privileges of NIX, typically 'NT AUTHORITY\NetworkService', and the ability of StreamStampImage to process the file. The encrypted file path can be generated using the shared, hard-coded secret key described in CVE-2025-35052. This vulnerability cannot be exploited as an 'anonymous' user as described in CVE-2025-35062.

EPSS

Процентиль: 20%
0.00064
Низкий

5.3 Medium

CVSS4

5 Medium

CVSS3

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 5
nvd
4 месяца назад

Newforma Info Exchange (NIX) '/UserWeb/Common/MarkupServices.ashx' 'StreamStampImage' accepts an encrypted file path and returns an image of the specified file. An authenticated attacker can read arbitrary files subject to the privileges of NIX, typically 'NT AUTHORITY\NetworkService', and the ability of StreamStampImage to process the file. The encrypted file path can be generated using the shared, hard-coded secret key described in CVE-2025-35052. This vulnerability cannot be exploited as an 'anonymous' user as described in CVE-2025-35062.

EPSS

Процентиль: 20%
0.00064
Низкий

5.3 Medium

CVSS4

5 Medium

CVSS3

Дефекты

CWE-22