CVE-2023-42660
MOVEit Transfer Machine Interface SQL Injection
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
In Progress MOVEit Transfer versions released before 2021.1.8 (13.1.8), 2022.0.8 (14.0.8), 2022.1.9 (14.1.9), 2023.0.6 (15.0.6), a SQL injection vulnerability has been identified in the MOVEit Transfer machine interface that could allow an authenticated attacker to gain unauthorized access to the MOVEit Transfer database. An attacker could submit a crafted payload to the MOVEit Transfer machine interface which could result in modification and disclosure of MOVEit database content.
En las versiones de MOVEit Transfer lanzadas antes de 2021.1.8 (13.1.8), 2022.0.8 (14.0.8), 2022.1.9 (14.1.9), 2023.0.6 (15.0.6), se ha identificado una vulnerabilidad de inyección SQL en la interfaz de la máquina MOVEit Transfer que podría permitir que un atacante autenticado obtenga acceso no autorizado a la base de datos de MOVEit Transfer. Un atacante podría enviar un payload manipulado a la interfaz de la máquina MOVEit Transfer, lo que podría provocar la modificación y divulgación del contenido de la base de datos de MOVEit.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2023-09-12 CVE Reserved
- 2023-09-20 CVE Published
- 2024-08-02 CVE Updated
- 2024-09-26 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CAPEC
- CAPEC-66: SQL Injection
References (2)
URL | Tag | Source |
---|---|---|
https://www.progress.com/moveit | Product |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://community.progress.com/s/article/MOVEit-Transfer-Service-Pack-September-2023 | 2023-09-22 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Progress Search vendor "Progress" | Moveit Transfer Search vendor "Progress" for product "Moveit Transfer" | < 2021.1.8 Search vendor "Progress" for product "Moveit Transfer" and version " < 2021.1.8" | - |
Affected
| ||||||
Progress Search vendor "Progress" | Moveit Transfer Search vendor "Progress" for product "Moveit Transfer" | >= 2022.0.0 < 2022.0.8 Search vendor "Progress" for product "Moveit Transfer" and version " >= 2022.0.0 < 2022.0.8" | - |
Affected
| ||||||
Progress Search vendor "Progress" | Moveit Transfer Search vendor "Progress" for product "Moveit Transfer" | >= 2022.1.0 < 2022.1.9 Search vendor "Progress" for product "Moveit Transfer" and version " >= 2022.1.0 < 2022.1.9" | - |
Affected
| ||||||
Progress Search vendor "Progress" | Moveit Transfer Search vendor "Progress" for product "Moveit Transfer" | >= 2023.0.0 < 2023.0.6 Search vendor "Progress" for product "Moveit Transfer" and version " >= 2023.0.0 < 2023.0.6" | - |
Affected
|