Exploited Vulnerabilities Daily
🌐 English

Home › Progress

CVE-2023-34362: Progress MOVEit Transfer

EPSS99.9%No. 109 of 1739 in KEV
CVE year2023listed the same year
Same vendor in KEV9
Same product1
FieldValue
VendorProgress
ProductMOVEit Transfer
NameProgress MOVEit Transfer SQL Injection Vulnerability
Added to KEV2023-06-02
US federal due date2023-06-23
Ransomware useKnown
CWECWE-89

CISA description

Progress MOVEit Transfer contains a SQL injection vulnerability that could allow an unauthenticated attacker to gain unauthorized access to MOVEit Transfer's database. Depending on the database engine being used (MySQL, Microsoft SQL Server, or Azure SQL), an attacker may be able to infer information about the structure and contents of the database in addition to executing SQL statements that alter or delete database elements.

NVD — CVE-2023-34362

Data from CISA's Known Exploited Vulnerabilities (KEV) catalog. EPSS is FIRST's estimated probability of exploitation activity in the next 30 days, refreshed weekly. Always follow the vendor's official guidance.
About this page

A Progress MOVEit Transfer vulnerability added to CISA's Known Exploited Vulnerabilities catalog on 2023-06-02.