---
id: CVE-2025-35056
title: >-
  Newforma Info Exchange (NIX) '/UserWeb/Common/MarkupServices.ashx'
  'StreamStampImage' accepts an encrypted file path and returns an image of the
  specified file
summary: >-
  Newforma Info Exchange (NIX) '/UserWeb/Common/MarkupServices.ashx'
  'StreamStampImage' accepts an encrypted file path and returns an image of the
  specified file. An authenticated attacker can read arbitrary files subject to
  the privileges…
severity: medium
cvss: 5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N'
cwe:
  - CWE-22
vendor: newforma
product: project_center
affected:
  - project_center < 2024.1
patched:
  - project_center 2024.1
published: '2025-10-09'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T13:10:00.200'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-35056'
references:
  - url: >-
      https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2025/va-25-282-01.json
    label: 9119a7d8-5eab-497f-8521-727c672e3725
  - url: 'https://www.cve.org/CVERecord?id=CVE-2025-35056'
    label: 9119a7d8-5eab-497f-8521-727c672e3725
  - url: 'https://www.cve.org/CVERecord?id=CVE-2025-35062'
    label: 9119a7d8-5eab-497f-8521-727c672e3725
tags:
  - nvd
epss: 0.00354
epssPercentile: 0.26986
ingestedAt: '2026-10-08T13:42:55.061Z'
---

## Overview

Newforma Info Exchange (NIX) '/UserWeb/Common/MarkupServices.ashx' 'StreamStampImage' accepts an encrypted file path and returns an image of the specified file. An authenticated attacker can read arbitrary files subject to the privileges of NIX, typically 'NT AUTHORITY\NetworkService', and the ability of StreamStampImage to process the file. The encrypted file path can be generated using the shared, hard-coded secret key described in CVE-2025-35052. This vulnerability cannot be exploited as an 'anonymous' user as described in CVE-2025-35062.

## Affected

- `project_center < 2024.1`

## Remediation

Upgrade past the affected range:

- `project_center 2024.1`
