CVE-2023-35708
In Progress MOVEit Transfer before 2021.0.8 (13.0.8), 2021.1.6 (13.1.6), 2022.0.6 (14.0.6), 2022.1.7 (14.1.7), and 2023.0.3 (15.0.3), a SQL injection vulnerability has been identified in the MOVEit Transfer web application that could allow an…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 96.7%, higher than 100% of all known CVEs. Patch or mitigate before the next change window.
Description
In Progress MOVEit Transfer before 2021.0.8 (13.0.8), 2021.1.6 (13.1.6), 2022.0.6 (14.0.6), 2022.1.7 (14.1.7), and 2023.0.3 (15.0.3), a SQL injection vulnerability has been identified in the MOVEit Transfer web application that could allow an unauthenticated attacker to gain unauthorized access to MOVEit Transfer's database. An attacker could submit a crafted payload to a MOVEit Transfer application endpoint that could result in modification and disclosure of MOVEit database content. These are fixed versions of the DLL drop-in: 2020.1.10 (12.1.10), 2021.0.8 (13.0.8), 2021.1.6 (13.1.6), 2022.0.6 (14.0.6), 2022.1.7 (14.1.7), and 2023.0.3 (15.0.3).
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 96.68% probability · 100th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-89
- Affected
- progress/moveit transfer
- Source
- cve@mitre.org
References
- https://community.progress.com/s/article/MOVEit-Transfer-Critical-Vulnerability-15June2023Mitigation, Patch, Vendor Advisory
- https://www.cisa.gov/news-events/alerts/2023/06/15/progress-software-releases-security-advisory-moveit-transfer-vulnerabilityThird Party Advisory, US Government Resource
- https://www.progress.com/security/moveit-transfer-and-moveit-cloud-vulnerabilityVendor Advisory
- https://community.progress.com/s/article/MOVEit-Transfer-Critical-Vulnerability-15June2023Mitigation, Patch, Vendor Advisory
- https://www.cisa.gov/news-events/alerts/2023/06/15/progress-software-releases-security-advisory-moveit-transfer-vulnerabilityThird Party Advisory, US Government Resource
- https://www.progress.com/security/moveit-transfer-and-moveit-cloud-vulnerabilityVendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.