Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-35056

Опубликовано: 09 окт. 2025
Источник: nvd
CVSS3: 5
EPSS Низкий

Описание

Newforma Info Exchange (NIX) '/UserWeb/Common/MarkupServices.ashx' 'StreamStampImage' accepts an encrypted file path and returns an image of the specified file. An authenticated attacker can read arbitrary files subject to the privileges of NIX, typically 'NT AUTHORITY\NetworkService', and the ability of StreamStampImage to process the file. The encrypted file path can be generated using the shared, hard-coded secret key described in CVE-2025-35052. This vulnerability cannot be exploited as an 'anonymous' user as described in CVE-2025-35062.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:newforma:project_center:*:*:*:*:*:*:*:*
Версия до 2024.1 (исключая)

EPSS

Процентиль: 20%
0.00064
Низкий

5 Medium

CVSS3

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 5
github
4 месяца назад

Newforma Info Exchange (NIX) '/UserWeb/Common/MarkupServices.ashx' 'StreamStampImage' accepts an encrypted file path and returns an image of the specified file. An authenticated attacker can read arbitrary files subject to the privileges of NIX, typically 'NT AUTHORITY\NetworkService', and the ability of StreamStampImage to process the file. The encrypted file path can be generated using the shared, hard-coded secret key described in CVE-2025-35052. This vulnerability cannot be exploited as an 'anonymous' user as described in CVE-2025-35062.

EPSS

Процентиль: 20%
0.00064
Низкий

5 Medium

CVSS3

Дефекты

CWE-22