CVE-2025-35055
Severity CVSS v4.0:
HIGH
Type:
CWE-22
Path Traversal
Publication date:
09/10/2025
Last modified:
22/10/2025
Description
Newforma Info Exchange (NIX) '/UserWeb/Common/UploadBlueimp.ashx' allows an authenticated attacker to upload an arbitrary file to any location writable by the NIX application. An attacker can upload and run a web shell or other content executable by the web server. An attacker can also delete directories. In Newforma before 2023.1, anonymous access is enabled by default (CVE-2025-35062), allowing an otherwise unauthenticated attacker to effectively authenticate as 'anonymous' and exploit this file upload vulnerability.
Impact
Base Score 4.0
8.70
Severity 4.0
HIGH
Base Score 3.x
8.80
Severity 3.x
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:newforma:project_center:*:*:*:*:*:*:*:* | 2023.1 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



