CVE-2023-35036 is a critical SQL injection vulnerability affecting Progress MOVEit Transfer versions before 2021.0.7, 2021.1.5, 2022.0.5, 2022.1.6, and 2023.0.2. This flaw allows unauthenticated attackers to gain unauthorized access to the MOVEit Transfer database, potentially leading to modification and disclosure of sensitive data. With a CVSS score of 9.1 (Critical), it presents a high risk due to its network-based attack vector, low attack complexity, and significant impact on confidentiality and integrity. While not yet listed in CISA's KEV catalog, the vulnerability has a high EPSS score and significant community discussion, with media reports confirming its active exploitation in the wild, including data breaches affecting organizations like the Louisiana DMV and New York City students.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2021.0.7CPE matchmatch criteria | cpe:2.3:a:progress:moveit_transfer:*:*:*:*:*:*:*:* | ||
>= 2021.1.0, < 2021.1.5CPE matchmatch criteria | cpe:2.3:a:progress:moveit_transfer:*:*:*:*:*:*:*:* | ||
>= 2022.0.0, < 2022.0.5CPE matchmatch criteria | cpe:2.3:a:progress:moveit_transfer:*:*:*:*:*:*:*:* | ||
>= 2022.1.0, < 2022.1.6CPE matchmatch criteria | cpe:2.3:a:progress:moveit_transfer:*:*:*:*:*:*:*:* | ||
>= 2023.0.0, < 2023.0.2CPE matchmatch criteria | cpe:2.3:a:progress:moveit_transfer:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.