Description
Newforma Info Exchange (NIX) '/DownloadWeb/hyperlinkredirect.aspx' provides an unauthenticated URL redirect via the 'nhl' parameter.
Problem types
CWE-601 URL Redirection to Untrusted Site ('Open Redirect')
Product status
Any version before 2024.1
2024.1
Credits
Shadron Gudmunson,Luke Rindels,Robert McCain,Asjha Stus,Adam Merrill,Ryan Kao,Brian Healy, Sandia National Laboratories Adversarial Modeling and Penetration Testing (AMPT)
References
raw.githubusercontent.com/...IT/white/2025/va-25-282-01.json (url)
www.cve.org/CVERecord?id=CVE-2025-35059 (url)