CVE-2025-35059

MEDIUM

Newforma Project Center < 2024.1 - Open Redirect

Title source: rule
STIX 2.1

Description

Newforma Info Exchange (NIX) '/DownloadWeb/hyperlinkredirect.aspx' provides an unauthenticated URL redirect via the 'nhl' parameter.

Scores

CVSS v3 4.3
EPSS 0.0003
EPSS Percentile 7.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-601
Status published
Products (1)
newforma/project_center < 2024.1
Published Oct 09, 2025
Tracked Since Feb 18, 2026