CVE-2023-34362 is a critical SQL injection vulnerability affecting Progress MOVEit Transfer and MOVEit Cloud that allows unauthenticated attackers to gain unauthorized access to the application's database. With a CVSS score of 9.8, this remotely exploitable flaw requires no user interaction or privileges, enabling threat actors to infer database structure and potentially alter or delete sensitive data. The vulnerability is currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog and has been leveraged in widespread ransomware campaigns, with functional exploit code available in frameworks such as Metasploit and Nuclei.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 14.0.5.45CPE matchmatch criteria | cpe:2.3:a:progress:moveit_cloud:*:*:*:*:*:*:*:* | ||
>= 14.1.0.0, < 14.1.6.97CPE matchmatch criteria | cpe:2.3:a:progress:moveit_cloud:*:*:*:*:*:*:*:* | ||
>= 15.0.0.0, < 15.0.2.39CPE matchmatch criteria | cpe:2.3:a:progress:moveit_cloud:*:*:*:*:*:*:*:* | ||
< 2021.0.7CPE matchmatch criteria | cpe:2.3:a:progress:moveit_transfer:*:*:*:*:*:*:*:* | ||
>= 2021.1.0, < 2021.1.5CPE matchmatch criteria | cpe:2.3:a:progress:moveit_transfer:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.