Unauthenticated URL Redirect Vulnerability in Newforma Info Exchange
CVE-2025-35059

5.3MEDIUM

Key Information:

Vendor

Newforma

Vendor
CVE Published:
9 October 2025

What is CVE-2025-35059?

The Newforma Info Exchange platform is vulnerable to unauthenticated URL redirects via the 'nhl' parameter in the '/DownloadWeb/hyperlinkredirect.aspx' endpoint. This vulnerability allows attackers to manipulate URLs, potentially leading to phishing attacks or redirection to malicious sites, compromising the security and integrity of user data. Organizations using Newforma Info Exchange should review their configurations and implement necessary security measures to mitigate this risk.

Affected Version(s)

Project Center 0 < 2024.1

Project Center 2024.1

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Shadron Gudmunson,Luke Rindels,Robert McCain,Asjha Stus,Adam Merrill,Ryan Kao,Brian Healy, Sandia National Laboratories Adversarial Modeling and Penetration Testing (AMPT)
.
CVE-2025-35059 : Unauthenticated URL Redirect Vulnerability in Newforma Info Exchange