CVE-2019-16383 is a critical SQL Injection vulnerability affecting Progress MOVEit Transfer versions 2018 SP2 (before 10.2.4), 2019 (before 11.0.2), and 2019.1 (before 11.1.1). An unauthenticated attacker can exploit this flaw via the REST API in MOVEit.DMZ.WebApi.dll to gain unauthorized access to the database. With a CVSS score of 9.4 (CRITICAL), this vulnerability allows for low-complexity network-based attacks that can lead to information disclosure and high impact to data integrity and availability. While not listed in CISA's KEV catalog, public exploit code exists on ExploitDB, indicating a potential for exploitation, though there is minimal community discussion or media coverage around this specific CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 10.2.0, < 10.2.4CPE matchmatch criteria | cpe:2.3:a:ipswitch:moveit_transfer:*:*:*:*:*:*:*:* | ||
>= 11.0, < 11.0.2CPE matchmatch criteria | cpe:2.3:a:ipswitch:moveit_transfer:*:*:*:*:*:*:*:* | ||
>= 11.1, < 11.1.1CPE matchmatch criteria | cpe:2.3:a:ipswitch:moveit_transfer:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.