CVE-2025-35060

Severity CVSS v4.0:
MEDIUM
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
09/10/2025
Last modified:
22/10/2025

Description

Newforma Info Exchange (NIX) provides a 'Send a File Transfer' feature that allows a remote, authenticated attacker to upload SVG files that contain JavaScript or other content that may be executed or rendered by a web browser using a mobile user agent.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:newforma:project_center:*:*:*:*:*:*:*:* 2024.1 (excluding)