CVE-2023-35708 is a critical SQL injection vulnerability in Progress MOVEit Transfer versions prior to 2023.0.3, allowing unauthenticated attackers to gain unauthorized database access, modify content, and disclose sensitive information. With a CVSS score of 9.8 (Critical), this flaw can be exploited remotely without user interaction, leading to complete compromise of confidentiality, integrity, and availability. While not currently listed on CISA's KEV catalog, exploit intelligence indicates public Nuclei templates exist, and the vulnerability has garnered significant community discussion and media coverage, suggesting a high potential for active exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2020.1.10CPE matchmatch criteria | cpe:2.3:a:progress:moveit_transfer:*:*:*:*:*:*:*:* | ||
>= 2021.0.6, < 2021.0.8CPE matchmatch criteria | cpe:2.3:a:progress:moveit_transfer:*:*:*:*:*:*:*:* | ||
>= 2021.1.4, < 2021.1.6CPE matchmatch criteria | cpe:2.3:a:progress:moveit_transfer:*:*:*:*:*:*:*:* | ||
>= 2022.0.4, < 2022.0.6CPE matchmatch criteria | cpe:2.3:a:progress:moveit_transfer:*:*:*:*:*:*:*:* | ||
>= 2022.1.5, < 2022.1.7CPE matchmatch criteria | cpe:2.3:a:progress:moveit_transfer:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.