216.73.216.197

CVE-2025-35060

· Published 09/10/2025 21:15 · Modified 09/10/2025 21:15

Labels: CVE-2025-35060 2025-10-099119a7d8-5eab-497f-8521-727c672e3725CVE-2025-35060CWE-79

Essential information

Published
09/10/2025 21:15
Modified
09/10/2025 21:15
Author
Creator
CVSS
5.1 MEDIUM (v3) 5.1 MEDIUM (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

Newforma Info Exchange (NIX) provides a 'Send a File Transfer' feature that allows a remote, authenticated attacker to upload SVG files that contain JavaScript or other content that may be executed or rendered by a web browser using a mobile user agent.

NVD status

Status
Received — CVE has been recently published to the CVE List and has been received by the NVD.
Source
9119a7d8-5eab-497f-8521-727c672e3725
NVD
View on NVD

Affected products (CPE)

ProductCPE
newforma / info exchange cpe:2.3:a:newforma:info_exchange:*:*:*:*:*:*:*:*

References