Threats Tagged 'cve-2025-35059'
View all threats tagged with 'cve-2025-35059'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cve-2025-35059'
Click on any threat for detailed analysis and mitigation recommendations
0 CVE-2025-35059 is an open redirect vulnerability in Newforma Project Center's Info Exchange component, specifically in the '/DownloadWeb/hyperlinkredirect.aspx' endpoint. The vulnerability allows unauthenticated attackers to craft URLs with the 'nhl' parameter that redirect users to untrusted external sites. This can facilitate phishing attacks or redirect users to malicious domains. The vulnerability has a CVSS score of 4.3 (medium severity), requires no authentication, but does require user interaction to follow the malicious link. There is no known exploit in the wild and no patches currently available. The impact primarily affects user trust and integrity rather than confidentiality or availability. European organizations using Newforma Project Center should be cautious, especially those in construction and project management sectors where this software is used. Mitigations include user education, monitoring for suspicious URLs, and implementing web filtering or URL validation at the application or network level. Join the discussion | CVE Database V5 | 10/09/2025, 20:21:56 UTC Added: 10/09/2025, 20:37:58 UTC |
Showing 1 to 1 of 1 result