CVE-2021-33894
HIGHProgress MOVEit Transfer SQL Injection in SILUtility.vb
Title source: llmDescription
In Progress MOVEit Transfer before 2019.0.6 (11.0.6), 2019.1.x before 2019.1.5 (11.1.5), 2019.2.x before 2019.2.2 (11.2.2), 2020.x before 2020.0.5 (12.0.5), 2020.1.x before 2020.1.4 (12.1.4), and 2021.x before 2021.0.1 (13.0.1), a SQL injection vulnerability exists in SILUtility.vb in MOVEit.DMZ.WebApp in the MOVEit Transfer web app. This could allow an authenticated attacker to gain unauthorized access to the database. Depending on the database engine being used (MySQL, Microsoft SQL Server, or Azure SQL), an attacker may be able to infer information about the structure and contents of the database and/or execute SQL statements that alter or delete database elements.
References (2)
Core 2
Core References
Product, Vendor Advisory x_refsource_misc
https://www.progress.com/moveit
Patch, Vendor Advisory x_refsource_confirm
https://community.progress.com/s/article/MOVEit-Transfer-Vulnerability-June-2021
Scores
CVSS v3
8.8
EPSS
0.0162
EPSS Percentile
82.1%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-89
Status
published
Products (1)
progress/moveit_transfer
< 2019.0.6
Published
Jun 09, 2021
Tracked Since
Feb 18, 2026