Showing 3 vulnerabilities on this page for moveit_transfer

Signals CISA KEV Ransomware Nuclei
Progress vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

MOVEit Transfer Privilege Escalation Vulnerability

Improper Authentication vulnerability in Progress MOVEit Transfer (SFTP module) can lead to Privilege Escalation.This issue affects MOVEit Transfer: from 2023.0.0 before 2023.0.12, from 2023.1.0 before 2023.1.7, from 2024.0.0 before 2024.0.3.

CWE-287Jul 29, 2024
CVSS7.3v3.1EPSS0.623%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

MOVEit Transfer Authentication Bypass Vulnerability

Improper Authentication vulnerability in Progress MOVEit Transfer (SFTP module) can lead to Authentication Bypass.This issue affects MOVEit Transfer: from 2023.0.0 before 2023.0.11, from 2023.1.0 before 2023.1.6, from 2024.0.0 before 2024.0.2.

CWE-287Jun 25, 2024
CVSS9.1v3.1EPSS81.5%PoCs3SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Progress MOVEit Transfer SQL Injection Vulnerability

In Progress MOVEit Transfer before 2021.0.6 (13.0.6), 2021.1.4 (13.1.4), 2022.0.4 (14.0.4), 2022.1.5 (14.1.5), and 2023.0.1 (15.0.1), a SQL injection vulnerability has been found in the MOVEit Transfer web application that could allow an unauthenticated attacker to gain access to MOVEit Transfer's database. Depending on the database engine being used (MySQL, Microsoft SQL Server, or Azure SQL), an attacker may be able to infer information about the structure and contents of the database, and exe

CWE-89Jun 2, 20231 related artifact
CVSS9.8v3.1EPSS>99.9%PoCs16SignalsListed in CISA KEVKnown ransomware use1 Nuclei templateSTIX